Skip to content
FIRERUN.

The BaaS & deploy-platform newsroom for builders

Subscribe

Vercel

Vercel Confirms a KVM Zero-Day Found by Its Sandbox Bounty

A researcher says he escaped a guest VM to host root. Vercel CEO Guillermo Rauch confirmed the KVM zero-day and promised a full write-up.

Abstract flat-vector editorial illustration for "Vercel Confirms a KVM Zero-Day Found by Its Sandbox Bounty"

Vercel CEO Guillermo Rauch confirmed Oct. 3 that a researcher found a zero-day in KVM, the Linux hypervisor layer that Vercel Sandbox leans on, through the company’s Sandbox bounty program. “We’ve confirmed a KVM 0day through our Vercel Sandbox bounty program,” Rauch wrote, adding that a full write-up is coming (Guillermo Rauch on X, Oct. 3).

What was reported

Researcher Paulos Yibelo said he had a “full VM escape zeroday,” going from guest to host root in industry-standard hypervisors. Rauch thanked Yibelo by name and called KVM the industry’s gold standard for Linux virtualization.

Vercel Sandbox runs customer code, including AI-agent output, in Firecracker microVMs on bare-metal EC2 hosts, according to the HackerOne program page. Firecracker relies on KVM. A flaw there sits underneath the isolation boundary Vercel is selling.

Cybersecurity News reported the payout at $50,000. That matches the top of the range Vercel set when it opened the program in August with a $1 million pool.

What is not public yet

Vercel has not released a CVE number, affected kernel versions or patch details. Rauch’s post promises a technical write-up without a date. Until it lands, the scope is Yibelo’s claim plus Rauch’s confirmation.

The take

This is the outcome a bounty is supposed to produce. Vercel put money on the table in August, a researcher cashed it, and the CEO confirmed the result publicly the same weekend instead of burying it.

The harder question comes with the write-up. A KVM flaw is not Vercel’s alone to fix, and every platform running untrusted agent code on shared hosts, from other sandbox vendors to anyone self-hosting microVMs, will want to know whether the bug needs a particular CPU, a guest kernel setting or admin rights inside the guest. Those details decide whether this is a Vercel story or an industry one.

For teams running agent code in Sandbox today, the practical step is to watch for that write-up and for any kernel advisory that follows. Firerun covered the program when it launched in August. The first big result is in, and the details are still to come.

Stay in the loop

Get new articles in your inbox

We'll only email you when a new article drops. Unsubscribe anytime.