{"slug": "vercel-confirms-a-kvm-zero-day-found-by-its-sandbox-bounty", "title": "Vercel Confirms a KVM Zero-Day Found by Its Sandbox Bounty", "summary": "Vercel CEO Guillermo Rauch confirmed on Oct. 3 that researcher Paulos Yibelo found a KVM zero-day through Vercel's Sandbox bounty program, reporting a \"full VM escape zeroday\" from guest to host root. Cybersecurity News reported the payout at $50,000, the top of the range Vercel set when it opened the program in August with a $1 million pool. Vercel has not released a CVE number, affected kernel versions or patch details, and Rauch promised a technical write-up without a date.", "body_md": "# Vercel Confirms a KVM Zero-Day Found by Its Sandbox Bounty\n\nA researcher says he escaped a guest VM to host root. Vercel CEO Guillermo Rauch confirmed the KVM zero-day and promised a full write-up.\n\nVercel CEO Guillermo Rauch confirmed Oct. 3 that a researcher found a zero-day in KVM, the Linux hypervisor layer that Vercel Sandbox leans on, through the company’s Sandbox bounty program. “We’ve confirmed a KVM 0day through our Vercel Sandbox bounty program,” Rauch wrote, adding that a full write-up is coming ([Guillermo Rauch on X, Oct. 3](https://x.com/rauchg/status/2106402024804020657)).\n\n## What was reported\n\nResearcher Paulos Yibelo said he had a “full VM escape zeroday,” going from guest to host root in industry-standard hypervisors. Rauch thanked Yibelo by name and called KVM the industry’s gold standard for Linux virtualization.\n\nVercel Sandbox runs customer code, including AI-agent output, in Firecracker microVMs on bare-metal EC2 hosts, according to the HackerOne program page. Firecracker relies on KVM. A flaw there sits underneath the isolation boundary Vercel is selling.\n\nCybersecurity News reported the payout at $50,000. That matches the top of the range Vercel set when it opened the program in August with a $1 million pool.\n\n## What is not public yet\n\nVercel has not released a CVE number, affected kernel versions or patch details. Rauch’s post promises a technical write-up without a date. Until it lands, the scope is Yibelo’s claim plus Rauch’s confirmation.\n\n## The take\n\nThis is the outcome a bounty is supposed to produce. Vercel put money on the table in August, a researcher cashed it, and the CEO confirmed the result publicly the same weekend instead of burying it.\n\nThe harder question comes with the write-up. A KVM flaw is not Vercel’s alone to fix, and every platform running untrusted agent code on shared hosts, from other sandbox vendors to anyone self-hosting microVMs, will want to know whether the bug needs a particular CPU, a guest kernel setting or admin rights inside the guest. Those details decide whether this is a Vercel story or an industry one.\n\nFor teams running agent code in Sandbox today, the practical step is to watch for that write-up and for any kernel advisory that follows. Firerun covered the program when it launched in August. The first big result is in, and the details are still to come.", "url": "https://wpnews.pro/news/vercel-confirms-a-kvm-zero-day-found-by-its-sandbox-bounty", "canonical_source": "https://firerun.io/vercel-sandbox-kvm-zero-day-bounty-2026/", "published_at": "2026-10-05 00:00:00+00:00", "updated_at": "2026-10-05 10:16:03.918385+00:00", "lang": "en", "topics": ["ai-safety", "ai-agents", "ai-infrastructure"], "entities": ["Vercel", "Guillermo Rauch", "Paulos Yibelo", "KVM", "Firecracker", "Vercel Sandbox", "HackerOne", "Amazon EC2"], "also_reported_by": [], "alternates": {"html": "https://wpnews.pro/news/vercel-confirms-a-kvm-zero-day-found-by-its-sandbox-bounty", "markdown": "https://wpnews.pro/news/vercel-confirms-a-kvm-zero-day-found-by-its-sandbox-bounty.md", "text": "https://wpnews.pro/news/vercel-confirms-a-kvm-zero-day-found-by-its-sandbox-bounty.txt", "jsonld": "https://wpnews.pro/news/vercel-confirms-a-kvm-zero-day-found-by-its-sandbox-bounty.jsonld"}}