Security researcher Paulos Yibelo posted an X screenshot showing a Vercel bug-bounty award for a vulnerability he described as a full virtual-machine escape. The alleged flaw would let a guest reach root on its host. Vercel CEO Guillermo Rauch identified Linux KVM as the affected hypervisor and said the company had confirmed a KVM zero-day through its Sandbox bounty program. Rauch called KVM an industry-standard solution for Linux virtualization.
Vercel uses Firecracker MicroVMs to sandbox AI agents. AWS created Firecracker, which relies on KVM, Linux's kernel-level hypervisor. The Register found no discussion of the claim on relevant mailing lists and asked Yibelo and Rauch for more information.
A guest-to-host escape could give an attacker control of the host server and potentially other guest machines. AWS and Google use KVM in their public clouds. Nutanix, HPE and Proxmox also depend on it. Firecracker is open source, so a confirmed vulnerability could affect deployments beyond Vercel.
The finding needs a responsible disclosure process. Possible fixes include hot-patching KVM and live-migrating virtual machines to hosts running patched Linux, but the operational impact is unknown. The claim could mark the second serious KVM bug of the year after the Januscape flaw. Vercel's bounty program offers up to $50,000, and observers say a finding of this severity should receive more.




Comments
No comments yet — be the first.
Open the discussion
No account or password needed — just enter your e-mail and we’ll send you a one-time sign-in link. First time here? You’re set up automatically.
Your rating will be applied automatically after you sign in.
Check your inbox
We’ve sent a sign-in link to …. Open it on this device — this tab will sign you in automatically.
Nothing arrived? Check your spam folder — and mark the mail as "Not spam" so it lands in your inbox next time.