
Vercel Confirms a KVM Zero-Day Found by Its Sandbox Bounty
A researcher says he escaped a guest VM to host root. Vercel CEO Guillermo Rauch confirmed the KVM zero-day and promised a full write-up.
Topic
20 articles tagged Security.

A researcher says he escaped a guest VM to host root. Vercel CEO Guillermo Rauch confirmed the KVM zero-day and promised a full write-up.

Supabase rolls Postgres 15.19/17.11 out to every project starting today, closing 44 CVEs and flagging four breaking changes that need manual follow-up.

Firebase's Admin SDKs finished shipping App Check replay protection, but a FlutterFire bug stops iOS and macOS from getting the short-lived tokens it needs.

Next.js shipped an unscheduled critical RCE patch for ImageResponse (CVSS 9.5), breaking the monthly security cadence Vercel set up in July.

Vercel replaced its $150-a-month team-wide add-on with $20-per-project Password Protection pricing on Pro, ending a bundle that priced every project at once.

Vercel brings AWS PrivateLink to Pro and Enterprise, letting Functions reach RDS, Aurora and Neon without a public-internet hop.

Two critical unauthenticated RCE bugs, one in AVIF image handling and one Windows-only, forced Next.js to patch a day early.

Vercel is offering hackers up to $50,000 per bug to break Sandbox isolation, weeks after OpenAI agents escaped a sandbox and breached Hugging Face.

Netlify's SSO login now routes on email domain alone, dropping the team ID field that locked out anyone who forgot it.

Firebase App Check added reCAPTCHA Enterprise as an attestation option for Android, Apple platforms and Flutter, matching the option web apps already had.

Supabase's alpha for scoped personal access tokens, live since August 10, closes a nearly three-year-old gap where any token controlled the whole account.

Vercel's Enterprise Managed Users reached general availability August 11, forcing SAML-only sign-in and directory-managed accounts on company domains.

A flaw in Vercel AI SDK's Codex and OpenCode harnesses let sandboxed code invoke host tools without the model ever generating the call.

Starting August 5, Supabase ignores explicit version numbers on Postgres extensions and installs the default version instead, closing a security gap.

Vercel Passport reached general availability July 31, gating internal apps and AI agents behind Okta, Entra ID, Auth0 or any OIDC provider.

New Netlify teams on Credit-based plans now get private projects automatically. Teams that signed up before July 28 keep the old public-by-default behavior.

React Router 7.18.0 closes a DoS in the manifest endpoint and an open-redirect bypass, both follow-ups to fixes shipped earlier in 2026 that didn't fully hold.

Vercel's new Next.js Security Release Program pre-announces patch dates and severity, then ships. Its first drop fixed 9 bugs, 4 of them high severity.

Vercel's AI SDK adds fingerprintTools and detectToolDrift to catch MCP servers that silently swap a tool's description or schema after an agent trusts it.

Vercel now masks Sensitive Environment Variable values in build output automatically, closing a leak into logs teams routinely share and store.