Skip to main content

Vendor/product archive

vercel / ai CVEs

Beta · best-effort

4 CVEs tagged to vercel / ai0 Critical, 0 High, 1 Medium, 3 Low, 0 Unrated.

CVE-2026-8769

Published May 17, 2026

A vulnerability was determined in vercel ai up to 3.0.97. The impacted element is the function createJsonResponseHandler/createJsonErrorResponseHandler of the file packages/provid…

CVSS 2.1 · Low
evidence mentions
4
Buzz score
22.6
Vendor/product tagsBeta · best-effort

CVE-2026-8768

Published May 17, 2026

A vulnerability was found in vercel ai up to 3.0.97. The affected element is the function validateDownloadUrl of the file packages/provider-utils/src/download-blob.ts of the compo…

CVSS 5.5 · Medium
evidence mentions
6
Buzz score
26.0
Vendor/product tagsBeta · best-effort

CVE-2026-8767

Published May 17, 2026

A vulnerability has been found in vercel ai up to 3.0.97. Impacted is the function run of the file .github/workflows/prettier-on-automerge.yml of the component PR Branch Name Inte…

CVSS 1.3 · Low
evidence mentions
4
Buzz score
22.6
Vendor/product tagsBeta · best-effort

CVE-2025-48985

Published Nov 7, 2025

A vulnerability in Vercel’s AI SDK has been fixed in versions 5.0.52, 5.1.0-beta.9, and 6.0.0-beta. This issue may have allowed users to bypass filetype whitelists when uploading…

CVSS 3.7 · Low
Vendor/product tagsBeta · best-effort
Showing 1-4 of 4 CVEsPage 1 of 1