Skip to content

Backport: Backport: fix(security): validate redirect targets in download functions to prevent SSRF bypass#13130

Merged
gr2m merged 3 commits intorelease-v5.0from
backport-pr-13127-to-release-v5.0
Mar 5, 2026
Merged

Backport: Backport: fix(security): validate redirect targets in download functions to prevent SSRF bypass#13130
gr2m merged 3 commits intorelease-v5.0from
backport-pr-13127-to-release-v5.0

Conversation

@vercel-ai-sdk
Copy link
Copy Markdown
Contributor

@vercel-ai-sdk vercel-ai-sdk bot commented Mar 5, 2026

This is an automated backport of #13127 to the release-v5.0 branch.

@tigent tigent bot added ai/core core functions like generateText, streamText, etc. Provider utils, and provider spec. ai/provider related to a provider package. Must be assigned together with at least one `provider/*` label bug Something isn't working as documented labels Mar 5, 2026
@gr2m

This comment was marked as resolved.

@gr2m gr2m marked this pull request as ready for review March 5, 2026 23:31
@gr2m gr2m merged commit c66afc5 into release-v5.0 Mar 5, 2026
30 of 31 checks passed
@gr2m gr2m deleted the backport-pr-13127-to-release-v5.0 branch March 5, 2026 23:31
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

ai/core core functions like generateText, streamText, etc. Provider utils, and provider spec. ai/provider related to a provider package. Must be assigned together with at least one `provider/*` label bug Something isn't working as documented

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant