A researcher says he escaped a guest VM to host root. Vercel CEO Guillermo Rauch confirmed the KVM zero-day and promised a full write-up.
Vercel CEO Guillermo Rauch confirmed Oct. 3 that a researcher found a zero-day in KVM, the Linux hypervisor layer that Vercel Sandbox leans on, through the company’s Sandbox bounty program. “We’ve confirmed a KVM 0day through our Vercel Sandbox bounty program,” Rauch wrote, adding that a full write-up is coming (Guillermo Rauch on X, Oct. 3).
What was reported #
Researcher Paulos Yibelo said he had a “full VM escape zeroday,” going from guest to host root in industry-standard hypervisors. Rauch thanked Yibelo by name and called KVM the industry’s gold standard for Linux virtualization.
Vercel Sandbox runs customer code, including AI-agent output, in Firecracker microVMs on bare-metal EC2 hosts, according to the HackerOne program page. Firecracker relies on KVM. A flaw there sits underneath the isolation boundary Vercel is selling.
Cybersecurity News reported the payout at $50,000. That matches the top of the range Vercel set when it opened the program in August with a $1 million pool.
What is not public yet #
Vercel has not released a CVE number, affected kernel versions or patch details. Rauch’s post promises a technical write-up without a date. Until it lands, the scope is Yibelo’s claim plus Rauch’s confirmation.
The take #
This is the outcome a bounty is supposed to produce. Vercel put money on the table in August, a researcher cashed it, and the CEO confirmed the result publicly the same weekend instead of burying it.
The harder question comes with the write-up. A KVM flaw is not Vercel’s alone to fix, and every platform running untrusted agent code on shared hosts, from other sandbox vendors to anyone self-hosting microVMs, will want to know whether the bug needs a particular CPU, a guest kernel setting or admin rights inside the guest. Those details decide whether this is a Vercel story or an industry one.
For teams running agent code in Sandbox today, the practical step is to watch for that write-up and for any kernel advisory that follows. Firerun covered the program when it launched in August. The first big result is in, and the details are still to come.