vercel Vulnerabilities and Affected Products
Vulnerabilities associated with ai.
Products
Clear product- next.js48 vulnerabilities
- ai3 vulnerabilities
- turborepo3 vulnerabilities
- ms2 vulnerabilities
- next2 vulnerabilities
- @ai-sdk/harness-codex1 vulnerability
- @ai-sdk/harness-opencode1 vulnerability
- AI SDK1 vulnerability
- flags1 vulnerability
- hyper1 vulnerability
- Nuxt Devtools1 vulnerability
- pkg1 vulnerability
- vercel1 vulnerability
| Vulnerability | Title and context | CVSS | EPSS | PoCs | Signals | STIX action |
|---|---|---|---|---|---|---|
CVE-2026-8769MEDIUM | vercel ai provider-utils response-handler.ts createJsonErrorResponseHandler resource consumptionA vulnerability was determined in vercel ai up to 3.0.97. The impacted element is the function createJsonResponseHandler/createJsonErrorResponseHandler of the file packages/provider-utils/src/response-handler.ts of the component provider-utils. This manipulation causes resource consumption. The attack may be initiated remotely. The exploit has been publicly disclosed and may be utilized. The vendor was contacted early about this disclosure but did not respond in any way. | CVSS5.3v4.0 | EPSS0.561% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2026-8768MEDIUM | vercel ai provider-utils download-blob.ts validateDownloadUrl server-side request forgeryA vulnerability was found in vercel ai up to 3.0.97. The affected element is the function validateDownloadUrl of the file packages/provider-utils/src/download-blob.ts of the component provider-utils. The manipulation results in server-side request forgery. The attack can be launched remotely. The exploit has been made public and could be used. The vendor was contacted early about this disclosure but did not respond in any way. CWE-918May 17, 2026 | CVSS6.9v4.0 | EPSS0.385% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
vercel ai PR Branch Name Interpolation prettier-on-automerge.yml run os command injectionA vulnerability has been found in vercel ai up to 3.0.97. Impacted is the function run of the file .github/workflows/prettier-on-automerge.yml of the component PR Branch Name Interpolation. The manipulation leads to os command injection. The attack can be initiated remotely. The complexity of an attack is rather high. The exploitability is considered difficult. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond i… | CVSS2.3v4.0 | EPSS4.26% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |