Low severity3.7NVD Advisory· Published Nov 7, 2025· Updated Jun 17, 2026
CVE-2025-48985
CVE-2025-48985
Description
A vulnerability in Vercel’s AI SDK has been fixed in versions 5.0.52, 5.1.0-beta.9, and 6.0.0-beta. This issue may have allowed users to bypass filetype whitelists when uploading files. All users are encouraged to upgrade.
More details: https://vercel.com/changelog/cve-2025-48985-input-validation-bypass-on-ai-sdk
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
ainpm | < 5.0.52 | 5.0.52 |
ainpm | >= 5.1.0-beta.0, < 5.1.0-beta.9 | 5.1.0-beta.9 |
Affected products
19- ghsa-coords8 versionspkg:npm/aipkg:apk/chainguard/kibana-8.19pkg:apk/chainguard/kibana-8.19-bitnamipkg:apk/chainguard/kibana-8.19-iamguardedpkg:apk/chainguard/kibana-9.1pkg:apk/chainguard/kibana-9.2pkg:apk/chainguard/kibana-9.2-iamguardedpkg:apk/chainguard/kibana-9.1-iamguarded
< 5.0.52+ 7 more
- (no CPE)range: < 5.0.52
- (no CPE)range: < 8.19.9-r0
- (no CPE)range: < 8.19.9-r0
- (no CPE)range: < 8.19.9-r0
- (no CPE)range: < 9.1.9-r0
- (no CPE)range: < 9.2.3-r0
- (no CPE)range: < 9.2.3-r0
- (no CPE)range: < 9.1.9-r0
cpe:2.3:a:vercel:ai:5.1.0:beta6:*:*:*:*:*:*+ 9 more
- cpe:2.3:a:vercel:ai:5.1.0:beta6:*:*:*:*:*:*
- cpe:2.3:a:vercel:ai:*:*:*:*:*:*:*:*range: <5.0.52
- cpe:2.3:a:vercel:ai:5.1.0:beta0:*:*:*:*:*:*
- cpe:2.3:a:vercel:ai:5.1.0:beta1:*:*:*:*:*:*
- cpe:2.3:a:vercel:ai:5.1.0:beta2:*:*:*:*:*:*
- cpe:2.3:a:vercel:ai:5.1.0:beta3:*:*:*:*:*:*
- cpe:2.3:a:vercel:ai:5.1.0:beta4:*:*:*:*:*:*
- cpe:2.3:a:vercel:ai:5.1.0:beta5:*:*:*:*:*:*
- cpe:2.3:a:vercel:ai:5.1.0:beta7:*:*:*:*:*:*
- cpe:2.3:a:vercel:ai:5.1.0:beta8:*:*:*:*:*:*
Patches
Vulnerability mechanics
References
5- github.com/vercel/ai/commit/930399bb9839a8baf3d349614106d78268775eednvdPatchWEB
- github.com/advisories/GHSA-rwvc-j5jr-mgvhghsaADVISORY
- nvd.nist.gov/vuln/detail/CVE-2025-48985ghsaADVISORY
- vercel.com/changelog/cve-2025-48985-input-validation-bypass-on-ai-sdknvdVendor AdvisoryWEB
- github.com/vercel/ai/issues/8881ghsaWEB
News mentions
0No linked articles in our index yet.