Skip to content

chore: upgrade ai to ^6.0.303 to address CVE-2026-8769 - #1722

Closed
claude[bot] wants to merge 2 commits into
mainfrom
cursor/cve/ai-sdk-provider-utils-4.0.57
Closed

claude[bot] wants to merge 2 commits into
mainfrom
cursor/cve/ai-sdk-provider-utils-4.0.57

Conversation

@claude

@claude claude Bot commented Oct 10, 2026 •

Copy link
Copy Markdown
Contributor

Fixes SOU-2197

Summary

Addresses CVE-2026-8769 (@ai-sdk/provider-utils uncontrolled resource consumption, patched in 4.0.33).

@ai-sdk/provider-utils is exact-pinned (4.0.23) by ai and every @ai-sdk/* provider package, so a lockfile refresh of provider-utils alone can't fix it. This PR bumps the top-level packages in packages/web to their latest releases within their current majors:

Package Before After
ai ^6.0.167 ^6.0.303
@ai-sdk/amazon-bedrock ^4.0.94 ^4.0.194
@ai-sdk/anthropic ^3.0.70 ^3.0.129
@ai-sdk/azure ^3.0.54 ^3.0.136
@ai-sdk/deepseek ^2.0.29 ^2.0.71
@ai-sdk/google ^3.0.64 ^3.0.131
@ai-sdk/google-vertex ^4.0.111 ^4.0.212
@ai-sdk/mistral ^3.0.30 ^3.0.70
@ai-sdk/openai ^3.0.53 ^3.0.125
@ai-sdk/openai-compatible ^2.0.41 ^2.0.81
@ai-sdk/react ^3.0.169 ^3.0.306
@ai-sdk/xai ^3.0.83 ^3.0.139

After the upgrade, every 4.x copy of @ai-sdk/provider-utils resolves to 4.0.57. No resolutions override is used.

Note on @ai-sdk/mcp

@ai-sdk/mcp@2.0.0-beta.11 (unchanged) still depends on @ai-sdk/provider-utils@5.0.0-beta.7. That prerelease falls outside the advisory's affected ranges (<3.0.28, >=4.0.0 <4.0.33, >=5.0.0 <5.0.1), so it isn't flagged. I tried moving to stable @ai-sdk/mcp@2.0.73 (provider-utils@5.0.58), but it targets the AI SDK v7 tool API and breaks typechecking against ai@6 (ToolExecutionOptions.context, function-valued tool description). That move belongs with an ai v7 migration, so it's out of scope here.

Verification

  • yarn why @ai-sdk/provider-utils: only 4.0.57 and 5.0.0-beta.7 remain.
  • yarn workspace @sourcebot/web test --run: 151 files, 1529 tests passed.
  • yarn workspace @sourcebot/web lint: clean.
  • tsc --noEmit in packages/web: no errors apart from static-asset imports that need the generated next-env.d.ts.
  • yarn workspace @sourcebot/web build: succeeded.

🤖 Generated with Claude Code


Note

Medium Risk
Touches the Ask/agent LLM dependency stack used in production chat flows; changes are semver-compatible bumps with no app code edits, but regressions in streaming or provider behavior are possible.

Overview
Bumps the Vercel AI SDK stack in packages/web to address CVE-2026-8769 (uncontrolled resource consumption in @ai-sdk/provider-utils). Because provider-utils is exact-pinned by ai and the provider packages, the fix comes from upgrading the top-level dependencies rather than a lockfile-only override.

ai moves from ^6.0.167 to ^6.0.303, with matching minor/patch bumps across @ai-sdk/amazon-bedrock, @ai-sdk/anthropic, @ai-sdk/azure, @ai-sdk/deepseek, @ai-sdk/google, @ai-sdk/google-vertex, @ai-sdk/mistral, @ai-sdk/openai, @ai-sdk/openai-compatible, @ai-sdk/react, and @ai-sdk/xai. The lockfile now resolves 4.x @ai-sdk/provider-utils to 4.0.57 (above the patched 4.0.33 floor).

@ai-sdk/mcp stays on 2.0.0-beta.11 (out of scope for this advisory). CHANGELOG records the ai upgrade under Unreleased → Fixed.

Reviewed by Cursor Bugbot for commit 2ea6090. Bugbot is set up for automated code reviews on this repo. Configure here.

Bumps ai and the @ai-sdk/* provider packages within their current majors so
that @ai-sdk/provider-utils resolves to 4.0.57 (patched floor 4.0.33).

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
@coderabbitai

coderabbitai Bot commented Oct 10, 2026 •

Copy link
Copy Markdown
Contributor

Important

Review skipped

Bot user detected.

To trigger a single review, invoke the @coderabbitai review command.

⚙️ Run configuration
  • Configuration used: Organization UI
  • Review profile: CHILL
  • Plan: Advanced
  • Run ID: 418fb5f0-1601-4d1b-8375-ee2fc17efef0

You can disable this status message by setting the reviews.review_status to false in the CodeRabbit configuration file.

Use the checkbox below for a quick retry:

  • 🔍 Trigger review
  • Autofix · Keep fixing CodeRabbit findings and required CI, and resolving merge conflicts

Comment @coderabbitai help to get the list of available commands.

@github-actions

Copy link
Copy Markdown
Contributor

@claude[bot] your pull request is missing a changelog!

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
@claude
claude Bot requested a review from brendan-kellam October 10, 2026 14:12
@github-actions

Copy link
Copy Markdown
Contributor

License Audit

❌ Audit failed to produce results. Check the workflow logs for details.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant