CVE-2026-8768 Details
Description
A vulnerability was found in vercel ai up to 3.0.97. The affected element is the function validateDownloadUrl of the file packages/provider-utils/src/download-blob.ts of the component provider-utils. The manipulation results in server-side request forgery. The attack can be launched remotely. The exploit has been made public and could be used. The vendor was contacted early about this disclosure but did not respond in any way.
A server-side request forgery (SSRF) vulnerability has been identified in the Vercel AI SDK, specifically in the '@ai-sdk/provider-utils' package, all versions prior to 3.0.97. The issue arises in the 'validateDownloadUrl' function within 'packages/provider-utils/src/download-blob.ts'. This vulnerability allows remote attackers to bypass URL validation and redirect requests to internal resources, exploiting a time-of-check to time-of-use (TOCTOU) logic error. Although the SDK includes a post-redirect validation step, it occurs too late to prevent the initial request from reaching internal services.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed May 18, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://gist.github.com/YLChen-007/07d149bd68adbee58165b4207a2abc71 | [email protected] | Not Applicable |
| https://gist.github.com/YLChen-007/cf7e47e4dda392f474ca77a66d1d847f | [email protected] | ExploitThird Party Advisory |
| https://vuldb.com/submit/811404 | [email protected] | Third Party AdvisoryVDB Entry |
| https://vuldb.com/submit/811405 | [email protected] | Third Party AdvisoryVDB Entry |
| https://vuldb.com/vuln/364393 | [email protected] | Third Party AdvisoryVDB Entry |
| https://vuldb.com/vuln/364393/cti | [email protected] | Permissions RequiredVDB Entry |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-918 | Server-Side Request Forgery (SSRF) | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| vercel ai | <= 3.0.97 |
CPE
Remediation
| |
Change History
4 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| May 19, 2026 | Initial Analysis | [email protected] |
| May 17, 2026 | New CVE Received | [email protected] |