# Vercel Confirms a KVM Zero-Day Found by Its Sandbox Bounty

> Source: <https://firerun.io/vercel-sandbox-kvm-zero-day-bounty-2026/>
> Published: 2026-10-05 00:00:00+00:00

# Vercel Confirms a KVM Zero-Day Found by Its Sandbox Bounty

A researcher says he escaped a guest VM to host root. Vercel CEO Guillermo Rauch confirmed the KVM zero-day and promised a full write-up.

Vercel CEO Guillermo Rauch confirmed Oct. 3 that a researcher found a zero-day in KVM, the Linux hypervisor layer that Vercel Sandbox leans on, through the company’s Sandbox bounty program. “We’ve confirmed a KVM 0day through our Vercel Sandbox bounty program,” Rauch wrote, adding that a full write-up is coming ([Guillermo Rauch on X, Oct. 3](https://x.com/rauchg/status/2106402024804020657)).

## What was reported

Researcher Paulos Yibelo said he had a “full VM escape zeroday,” going from guest to host root in industry-standard hypervisors. Rauch thanked Yibelo by name and called KVM the industry’s gold standard for Linux virtualization.

Vercel Sandbox runs customer code, including AI-agent output, in Firecracker microVMs on bare-metal EC2 hosts, according to the HackerOne program page. Firecracker relies on KVM. A flaw there sits underneath the isolation boundary Vercel is selling.

Cybersecurity News reported the payout at $50,000. That matches the top of the range Vercel set when it opened the program in August with a $1 million pool.

## What is not public yet

Vercel has not released a CVE number, affected kernel versions or patch details. Rauch’s post promises a technical write-up without a date. Until it lands, the scope is Yibelo’s claim plus Rauch’s confirmation.

## The take

This is the outcome a bounty is supposed to produce. Vercel put money on the table in August, a researcher cashed it, and the CEO confirmed the result publicly the same weekend instead of burying it.

The harder question comes with the write-up. A KVM flaw is not Vercel’s alone to fix, and every platform running untrusted agent code on shared hosts, from other sandbox vendors to anyone self-hosting microVMs, will want to know whether the bug needs a particular CPU, a guest kernel setting or admin rights inside the guest. Those details decide whether this is a Vercel story or an industry one.

For teams running agent code in Sandbox today, the practical step is to watch for that write-up and for any kernel advisory that follows. Firerun covered the program when it launched in August. The first big result is in, and the details are still to come.
