CVE-2026-8768Disclosure(vercel / ai)

MEDIUMCVSS 7.3 · HIGH

Exploit discussion active in current signal (1 latest mentions)

Immediate actions

  • Patch vercel ai systems immediately
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft

Recommended action window: High priority (within 72h)

NVD description

A vulnerability was found in vercel ai up to 3.0.97. The affected element is the function validateDownloadUrl of the file packages/provider-utils/src/download-blob.ts of the component provider-utils. The manipulation results in server-side request forgery. The attack can be launched remotely. The exploit has been made public and could be used. The vendor was contacted early about this disclosure but did not respond in any way.

4.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-918

Priority

MEDIUM

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • ai

Threat summary

  • Public PoC and exploit tooling are both present
  • Patch or workaround signal is available
  • 5 mentions across 4 observed days
  • Momentum state: stable

What's happening

  • Exploit tool or code specified in 1 signal
  • PoC mentioned or linked in 2 signals
  • Patch or workaround mentioned in 2 signals
  • Technical details provided in 5 signals
  • Disclosure: 3 classified signals
  • Peaked 2d ago at 2 mentions (2026-05-18); latest day: 1
  • 5 total mentions across 4 days

Affected systems

Vendors
Products
ai

Deep dive

Activity timeline5 mentions / 4d
01122Mentions · 2026-05-17: 1Mentions · 2026-05-18: 2Mentions · 2026-05-29: 1Mentions · 2026-06-22: 1PoC Mentioned / Linked · 2026-05-18: 1PoC Mentioned / Linked · 2026-05-29: 1Exploit Tool / Code · 2026-05-18: 1Patch / Workaround · 2026-05-18: 1Patch / Workaround · 2026-05-29: 1Technical Details · 2026-05-17: 1Technical Details · 2026-05-18: 2Technical Details · 2026-05-29: 1Technical Details · 2026-06-22: 105-1705-1805-2906-22
Signal classification2 categories
Disclosure
360.0%
Exploit
240.0%
Referenced assets2 URLs
Classification over time
DateTotalLabels
2026-05-171
Disclosure1
2026-05-182
Disclosure1Exploit1
2026-05-291
Exploit1
2026-06-221
Disclosure1
Full discourse5 posts
  • AI Heartland@peaks2314
    Exploit

    🚨 Vercel AI SDK SSRF(リモート攻撃可能) ▼何が起きた provider-utils の validateDownloadUrl に CVE-2026-8768(CVSS 7.3)。v3.0.97 以下でSSRFが成立し、内部ネットワークへのリクエスト送信が可能。エクスプロイト公開済み。 ▼影響 vercel/ai v3.0.97 以下を使用するアプリケーション ▼対応 最新バージョンへアップデート。ベンダー未回答のため公式パッチ未確認の場合は、外部URLを受け取る処理で入力検証を追加。

    Post summary

    CVE‑2026‑8768 is an SSRF flaw in Vercel AI SDK v3.0.97 and earlier. An exploit has been published; users should upgrade or apply input validation as a workaround.

    1001097
    3.0K followersView on X
  • Joey Romaine 🇺🇸 |=★=|@Tank23x0
    Disclosure

    CVE-2026-8768: high severity (CVSS 7.3). exploit has a remote code execution issue worth scoping now. The calm team is usually the team that practiced the boring parts.

    Post summary

    The post briefly outlines CVE‑2026‑8768’s high CVSS score and remote code execution risk but provides no evidence of exploitation, PoC, or available mitigation.

    1000053
    340 followersView on X
  • DFIR Lab@DFIR_Lab
    Exploit

    🚨 HIGH severity CVE-2026-8768 (CVSS 7.3) affects Vercel AI ≤3[.]0[.]97. Server-Side Request Forgery in validateDownloadUrl function. Exploit public. Vendor unresponsive. Update immediately. #CVE #Vulnerability #PatchNow https://t.co/5rSvSHK7dj

    Post summary

    CVE‑2026‑8768 is a high‑severity Server‑Side Request Forgery in Vercel AI, publicly exploitable; vendors are unresponsive, so users must update immediately to mitigate.

    0000060
    31 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-8768 A vulnerability was found in vercel ai up to 3.0.97. The affected element is the function validateDownloadUrl of the file packages/provider-utils/src/download-blob.ts o… https://www.cve.org/CVERecord?id=CVE-2026-8768

    Post summary

    A new vulnerability (CVE-2026-8768) in Vercel AI’s validateDownloadUrl function has been disclosed, detailing the affected code location but providing no PoC, exploit, patch, or active exploitation information.

    00000195
    57.5K followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-8768 Server-Side Request Forgery in Vercel AI Up to 3.0.97 Provider-Utils https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-8768

    Post summary

    CVE-2026-8768 is disclosed as a server‑side request forgery affecting Vercel AI up to version 3.0.97, with no PoC, exploit, active use, patch, or debunking information provided.

    0000098
    4.0K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appvercelai---

Explore more