Vercel’s $1 million bug-bounty challenge for its Firecracker-based microVM sandbox received 1,285 reports and validated one Critical, seven High, 15 Medium, 49 Low, and 19 informational findings. The sandbox is used to isolate untrusted AI-agent code; Vercel had committed roughly $325,000 in rewards, and said no submission demonstrated access to real customer data.
The most serious reports disclosed two independent, nonpublic Linux kernel networking-stack flaws: one can expose host-kernel memory and the other can deterministically crash the host. Fixes remain under private review and CVE assignments are pending; the issues may affect cloud-isolation designs beyond Vercel. Trail of Bits also identified control-plane trust concerns involving values returned by guest microVM software, while Vercel used an agentic triage system to deduplicate reports and run researcher proof-of-concept exploits in a live sandbox.

See affected versions and whether adversaries are exploiting it.
5 events from the most recent confirmed update back to the earliest known activity.
Vercel ran a bug-bounty challenge for its Firecracker-based Sandbox environment, combining HackerOne black-box testing with Trail of Bits white-box testing. The program offered a $1 million reward pool and ran through September 1.
From 1,285 submitted reports, Vercel had validated one critical, seven high, 15 medium, 49 low, and 19 informational findings, with approximately $325,000 in committed payouts. No report demonstrated access to real Vercel customer data.
Facing the report volume, Vercel developed an agentic triage system using its Eve framework and Kimi K3, removing human review from the triage loop. The agent checks policy compliance, detects duplicates, retrieves source code, and runs researcher proofs of concept in a real Vercel Sandbox.
Trail of Bits produced 20 findings in its white-box assessment, including that Vercel's control plane accepted values returned by software inside guest microVMs. It recommended treating values crossing the guest boundary as tenant-controlled unless derived server-side or protected by a guest-inaccessible signing key.
Researchers identified two independent undisclosed Linux kernel networking-stack vulnerabilities: one could disclose host-kernel memory and the other could deterministically crash the host. Vercel said fixes were under private review and CVE assignments remained pending.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See whether adversaries are exploiting this yet, and where the affected versions run in your environment.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.