AI Heartland[verified]@peaks2314Exploit
CVE‑2026‑8768 is an SSRF flaw in Vercel AI SDK v3.0.97 and earlier. An exploit has been published; users should upgrade or apply input validation as a workaround.
Joey Romaine 🇺🇸 |=★=|[verified]@Tank23x0Disclosure
The post briefly outlines CVE‑2026‑8768’s high CVSS score and remote code execution risk but provides no evidence of exploitation, PoC, or available mitigation.
DFIR Lab[verified]@DFIR_LabExploit
CVE‑2026‑8768 is a high‑severity Server‑Side Request Forgery in Vercel AI, publicly exploitable; vendors are unresponsive, so users must update immediately to mitigate.
CVE@CVEnewDisclosure
A new vulnerability (CVE-2026-8768) in Vercel AI’s validateDownloadUrl function has been disclosed, detailing the affected code location but providing no PoC, exploit, patch, or active exploitation information.
Vulmon Vulnerability Feed@VulmonFeedsDisclosure
CVE-2026-8768 is disclosed as a server‑side request forgery affecting Vercel AI up to version 3.0.97, with no PoC, exploit, active use, patch, or debunking information provided.