
Vercel Puts $1M on the Line to Prove Its Sandbox Holds
Vercel is offering hackers up to $50,000 per bug to break Sandbox isolation, weeks after OpenAI agents escaped a sandbox and breached Hugging Face.
Topic
13 articles tagged Security.

Vercel is offering hackers up to $50,000 per bug to break Sandbox isolation, weeks after OpenAI agents escaped a sandbox and breached Hugging Face.

Netlify's SSO login now routes on email domain alone, dropping the team ID field that locked out anyone who forgot it.

Firebase App Check added reCAPTCHA Enterprise as an attestation option for Android, Apple platforms and Flutter, matching the option web apps already had.

Supabase's alpha for scoped personal access tokens, live since August 10, closes a nearly three-year-old gap where any token controlled the whole account.

Vercel's Enterprise Managed Users reached general availability August 11, forcing SAML-only sign-in and directory-managed accounts on company domains.

A flaw in Vercel AI SDK's Codex and OpenCode harnesses let sandboxed code invoke host tools without the model ever generating the call.

Starting August 5, Supabase ignores explicit version numbers on Postgres extensions and installs the default version instead, closing a security gap.

Vercel Passport reached general availability July 31, gating internal apps and AI agents behind Okta, Entra ID, Auth0 or any OIDC provider.

New Netlify teams on Credit-based plans now get private projects automatically. Teams that signed up before July 28 keep the old public-by-default behavior.

React Router 7.18.0 closes a DoS in the manifest endpoint and an open-redirect bypass, both follow-ups to fixes shipped earlier in 2026 that didn't fully hold.

Vercel's new Next.js Security Release Program pre-announces patch dates and severity, then ships. Its first drop fixed 9 bugs, 4 of them high severity.

Vercel's AI SDK adds fingerprintTools and detectToolDrift to catch MCP servers that silently swap a tool's description or schema after an agent trusts it.

Vercel now masks Sensitive Environment Variable values in build output automatically, closing a leak into logs teams routinely share and store.