CVE-2025-48985: Input Validation Bypass on AI SDK
security vulnerability A low-severityin Vercel's AI SDK was responsibly disclosed, and has been fixed for 5.0.52, 6.0.0-beta.* The issue may have allowed users to bypass filetype whitelists when uploading files. Vercel customers are encouraged to upgrade to the latest version. Read more details…
Sources
- T1CVE-2025-48985: Input Validation Bypass on AI SDKVercel (blog + changelog)