Skip to content

chore(deps): update dependency ai to v5.0.52 [security]#42

Open
renovate[bot] wants to merge 1 commit into
mainfrom
renovate/npm-ai-vulnerability
Open

chore(deps): update dependency ai to v5.0.52 [security]#42
renovate[bot] wants to merge 1 commit into
mainfrom
renovate/npm-ai-vulnerability

Conversation

@renovate

@renovate renovate Bot commented Nov 7, 2025

Copy link
Copy Markdown
Contributor

This PR contains the following updates:

Package Change Age Confidence
ai (source) 5.0.165.0.52 age confidence

Vercel’s AI SDK's filetype whitelists can be bypassed when uploading files

CVE-2025-48985 / GHSA-rwvc-j5jr-mgvh

More information

Details

A vulnerability in Vercel’s AI SDK has been fixed in versions 5.0.52, 5.1.0-beta.9, and 6.0.0-beta. This issue may have allowed users to bypass filetype whitelists when uploading files. All users are encouraged to upgrade.

Severity

  • CVSS Score: 3.7 / 10 (Low)
  • Vector String: CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N

References

This data is provided by the GitHub Advisory Database (CC-BY 4.0).


Release Notes

vercel/ai (ai)

v5.0.45

Patch Changes
  • 76024fc: fix(ai): fix static tool call and result detection when dynamic is undefined
  • 93d8b60: fix(ai): do not filter zero-length text parts that have provider options
  • d8eb31f: fix(ai): fix webp image detection from base64

v5.0.44

Patch Changes

v5.0.43

Patch Changes

v5.0.42

Patch Changes
  • de5c066: fix(ai): forwarded providerExecuted flag in validateUIMessages

v5.0.41

Patch Changes
  • cd91e4b: fix(ai): use correct type for reasoning outputs

v5.0.40

Patch Changes

v5.0.39

Patch Changes
  • a0a725f: feat (ai): export createGateway

v5.0.38

Patch Changes

v5.0.37

Patch Changes
  • d6785d7: feat (ai): add tool and agent helpers

v5.0.36

Patch Changes
  • ccc2ded: feat (ai): export gateway provider

v5.0.35

Patch Changes

v5.0.34

Patch Changes

v5.0.33

Patch Changes

v5.0.32

Patch Changes

v5.0.31

Patch Changes

v5.0.30

Patch Changes
  • 7fcc6be: feat(ai): throw InvalidArgumentError when messages is not provided

v5.0.29

Patch Changes
  • e0e9449: feat(ui): sent isAbort, isDisconnect, isError in useChat onFinish callback

v5.0.28

Patch Changes
  • 4b81e7d: fix(ai): remove vitest dependency from test exports
  • d68a4f2: feat(ai): log warnings

v5.0.27

Patch Changes
  • ca40fac: feat(ai): support custom download functions (experimental)

v5.0.26

Patch Changes

v5.0.25

Patch Changes

v5.0.24

Patch Changes
  • f8f3682: fix: call onFinish when stream is cancelled in toUIMessageStream

    Previously, onFinish was only called on normal stream completion. Now it's also called when the reader is cancelled (e.g., browser close, navigation), ensuring partial messages are persisted.

  • Updated dependencies

v5.0.23

Patch Changes
  • 5099b3d: fix(ai): make chat.addToolResult() compatible with dynamic tool calls
  • 7a2bf8d: fix(ai): support loop breaking behavior in async iterable stream
  • Updated dependencies

v5.0.22

Patch Changes

v5.0.21

Patch Changes

v5.0.20

Patch Changes
  • 8a87693: fix(ai) Make sure warnings promise in streamObject is resolved and properly collects and passes warnings

v5.0.19

Patch Changes
  • 8da6e9c: fix(ai): use parsed tool input if possible when validation fails

v5.0.18

Patch Changes

v5.0.17

Patch Changes
  • 4176ecb: feat(ai): add reasoning text to generateObject result
  • 20f23f9: feat(ai): export LanguageModelMiddleware type

Configuration

📅 Schedule: (UTC)

  • Branch creation
    • At any time (no schedule defined)
  • Automerge
    • At any time (no schedule defined)

🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.

Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.

🔕 Ignore: Close this PR and you won't be reminded about this update again.


  • If you want to rebase/retry this PR, check this box

This PR was generated by Mend Renovate. View the repository job log.

@renovate renovate Bot force-pushed the renovate/npm-ai-vulnerability branch from 8f291cf to 459db8b Compare December 31, 2025 16:54
@renovate renovate Bot force-pushed the renovate/npm-ai-vulnerability branch 2 times, most recently from 48dd6ba to a1cbda4 Compare January 23, 2026 19:07
@renovate renovate Bot force-pushed the renovate/npm-ai-vulnerability branch from a1cbda4 to 5374a03 Compare March 2, 2026 19:35
@renovate renovate Bot changed the title chore(deps): update dependency ai to v5.0.52 [security] chore(deps): update dependency ai to v5.0.52 [security] - autoclosed Mar 27, 2026
@renovate renovate Bot closed this Mar 27, 2026
@renovate renovate Bot deleted the renovate/npm-ai-vulnerability branch March 27, 2026 02:01
@renovate renovate Bot changed the title chore(deps): update dependency ai to v5.0.52 [security] - autoclosed chore(deps): update dependency ai to v5.0.52 [security] Mar 30, 2026
@renovate renovate Bot reopened this Mar 30, 2026
@renovate renovate Bot force-pushed the renovate/npm-ai-vulnerability branch 2 times, most recently from 5374a03 to 3df1d06 Compare March 30, 2026 21:52
@renovate renovate Bot force-pushed the renovate/npm-ai-vulnerability branch from 3df1d06 to 83bc34f Compare April 29, 2026 18:11
@renovate renovate Bot force-pushed the renovate/npm-ai-vulnerability branch from 83bc34f to ae7b110 Compare May 12, 2026 12:46
@renovate renovate Bot force-pushed the renovate/npm-ai-vulnerability branch from ae7b110 to 68b9429 Compare May 28, 2026 20:53
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants