Vercel Sandbox (3 Oct): CEO confirms KVM zero-day guest→host root escape — $50k bounty to Paulos Yibelo; write-up pending; no CVE/CVSS yet
Vercel CEO Guillermo Rauch confirmed on X (3 October 2026) that Vercel validated a KVM zero-day through its Sandbox bug-bounty program (HackerOne), calling out impact to “the industry’s gold standard solution for Linux virtualization.” Independent researcher Paulos Yibelo publicly described a full VM escape (guest to host root). Vercel Sandbox runs customer/AI-agent workloads inside Firecracker microVMs on KVM; the claimed break is the microVM/host isolation boundary, not the inner Linux container. Wire reporting (Tech Insider 4 Oct; Cyber Security News 4 Oct; HN link to Rauch post) says Vercel paid US$50,000 (reported maximum single-report tier for that program) and that a full technical write-up is still coming. As of this pass: no public CVE id, no public CVSS, no published affected KVM/Firecracker/kernel version list, no patch notes, and no confirmed exploitation in the wild. Other Firecracker-on-KVM platforms are not confirmed affected. Wire-primary until Vercel’s write-up / CVE lands — then switch primary_url. Primary confirmation: Rauch X post; context: Vercel Sandbox HackerOne policy (Firecracker microVM→EC2 host is the trust boundary); wires: Tech Insider / CSN 4 Oct.
- Product
- Linux KVM (claimed); Vercel Sandbox (Firecracker microVM on KVM) — disclosure channel
- Versions
- Not published — no CVE / affected KVM, Firecracker, or host-kernel version list in public sources as of 4 Oct 2026. Full write-up pending from Vercel.
- Exploited in Australia?
- unknown
- Patch to
- No public patch notes yet. Watch Vercel Sandbox / PSIRT write-up and any CVE assignment before changing agent-sandbox posture. Do not invent floors. Inventory Firecracker/KVM sandbox hosts used for untrusted or AI-generated code; treat as wire until vendor technical detail lands.
Primary: Guillermo Rauch (Vercel CEO) — X confirmation of KVM 0-day via Sandbox bounty (3 Oct 2026) · Vendor: Vercel Sandbox HackerOne bounty policy (Firecracker microVM → EC2 host trust boundary) · Tech Insider — Vercel confirms KVM zero-day, $50k bounty; no CVE yet (4 Oct 2026)
