cd /news/ai-safety/vercel-confirms-a-kvm-zero-day-found… · home › topics › ai-safety › article
[ARTICLE · art-145308] src=firerun.io ↗ pub= topic=ai-safety verified=true sentiment=· neutral

Vercel Confirms a KVM Zero-Day Found by Its Sandbox Bounty

Vercel CEO Guillermo Rauch confirmed on Oct. 3 that researcher Paulos Yibelo found a KVM zero-day through Vercel's Sandbox bounty program, reporting a "full VM escape zeroday" from guest to host root. Cybersecurity News reported the payout at $50,000, the top of the range Vercel set when it opened the program in August with a $1 million pool. Vercel has not released a CVE number, affected kernel versions or patch details, and Rauch promised a technical write-up without a date.

read2 min views1 publishedOct 5, 2026
Vercel Confirms a KVM Zero-Day Found by Its Sandbox Bounty
Image: Firerun (auto-discovered)

A researcher says he escaped a guest VM to host root. Vercel CEO Guillermo Rauch confirmed the KVM zero-day and promised a full write-up.

Vercel CEO Guillermo Rauch confirmed Oct. 3 that a researcher found a zero-day in KVM, the Linux hypervisor layer that Vercel Sandbox leans on, through the company’s Sandbox bounty program. “We’ve confirmed a KVM 0day through our Vercel Sandbox bounty program,” Rauch wrote, adding that a full write-up is coming (Guillermo Rauch on X, Oct. 3).

What was reported #

Researcher Paulos Yibelo said he had a “full VM escape zeroday,” going from guest to host root in industry-standard hypervisors. Rauch thanked Yibelo by name and called KVM the industry’s gold standard for Linux virtualization.

Vercel Sandbox runs customer code, including AI-agent output, in Firecracker microVMs on bare-metal EC2 hosts, according to the HackerOne program page. Firecracker relies on KVM. A flaw there sits underneath the isolation boundary Vercel is selling.

Cybersecurity News reported the payout at $50,000. That matches the top of the range Vercel set when it opened the program in August with a $1 million pool.

What is not public yet #

Vercel has not released a CVE number, affected kernel versions or patch details. Rauch’s post promises a technical write-up without a date. Until it lands, the scope is Yibelo’s claim plus Rauch’s confirmation.

The take #

This is the outcome a bounty is supposed to produce. Vercel put money on the table in August, a researcher cashed it, and the CEO confirmed the result publicly the same weekend instead of burying it.

The harder question comes with the write-up. A KVM flaw is not Vercel’s alone to fix, and every platform running untrusted agent code on shared hosts, from other sandbox vendors to anyone self-hosting microVMs, will want to know whether the bug needs a particular CPU, a guest kernel setting or admin rights inside the guest. Those details decide whether this is a Vercel story or an industry one.

For teams running agent code in Sandbox today, the practical step is to watch for that write-up and for any kernel advisory that follows. Firerun covered the program when it launched in August. The first big result is in, and the details are still to come.

── more in #ai-safety 4 stories · sorted by recency
── more on @vercel 3 stories trending now
sponsored brought to you by zahid.host 4,200+ EU-deployed projects
reading about agents? ship yours in a single git push.

Run your AI side-project on zahid.host

EU-based hosting, git-push deploys, automatic HTTPS, no cold starts. Free tier with a custom domain — perfect for shipping the agent you just read about.

$git push zahid main
→ Live at https://your-agent.zahid.host ✓
Get free account → Pricing
from €0/mo · no card required
LIVE [news/vercel-confirms-a-kv…] indexed:0 read:2min 2026-10-05 · —