@ai-sdk/provider-utils is vulnerable to Server-Side Request Forgery (SSRF)
74
High Risk
The downloadBlob helper in @ai-sdk/provider-utils fetches a caller-supplied URL without validating its protocol, hostname, or destination IP. The fix introduces a shared validateDownloadUrl utility that rejects non-HTTP(S) schemes, loopback, link-local, and private IPv4 and IPv6 ranges before any network request is made. The fix also validates the URL after redirects.
You are affected if you are using a version that falls within the vulnerable range.
@ai-sdk/provider-utils is vulnerable to Server-Side Request Forgery (SSRF) in versions 0.0.1 - 4.0.19.
Upgrade the @ai-sdk/provider-utils library to the patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

SOC 2Compliant
ISO 27001Compliant