Vercel confirmed a KVM zero-day after security researcher Paulos Yibelo reported a full virtual machine escape through its Vercel Sandbox bug bounty program. Yibelo said code running inside a guest could obtain root access on the host, and Vercel awarded him its maximum single-report bounty of $50,000. Vercel Sandbox runs untrusted workloads, including AI-agent code, in Firecracker microVMs on bare-metal Amazon EC2 hosts; the reported escape crosses the service’s primary isolation boundary.
The exploit chain, affected versions, prerequisites, CVE identifier, and patch status remain undisclosed, limiting independent assessment of exposure and remediation requirements. Vercel CEO Guillermo Rauch said a technical write-up would follow. The available statements do not establish customer data theft, widespread exploitation, or exposure across all KVM deployments. Security teams using Vercel Sandbox should monitor Vercel’s advisories for affected configurations and remediation guidance rather than assume the finding applies to every KVM environment.

See affected versions and whether adversaries are exploiting it.
5 events from the most recent confirmed update back to the earliest known activity.
Yibelo announced a claimed guest-to-host escape granting host root access and shared the bounty notification. The announcement did not disclose an exploit chain, CVE identifier, affected versions, exploitation prerequisites, or a patch.
Vercel opened its $1 million Sandbox challenge, requiring a live proof of concept demonstrating a broken security boundary rather than a finding based solely on code review.
Vercel CEO Guillermo Rauch separately confirmed a KVM zero-day and said a full technical write-up would follow. His statement did not establish that all KVM deployments, Firecracker installations, or cloud providers were vulnerable.
Vercel awarded Yibelo $50,000 for the vulnerability report, the Sandbox program's maximum single-report payment. The bounty notification later shared publicly did not reveal the root cause or establish that customer information had been accessed.
Paulos Yibelo submitted a vulnerability through the Vercel Sandbox bug bounty program that he said allowed code inside a guest virtual machine to obtain root access on its host.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See whether adversaries are exploiting this yet, and where the affected versions run in your environment.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.