Vercel has confirmed a KVM zero-day vulnerability after security researcher Paulos Yibelo reported a full virtual machine escape that, he says, allows code inside a guest to gain root access on the host.
The discovery came through the Vercel Sandbox bug bounty program, raising concerns about a security boundary used to contain untrusted workloads and AI agents.
Yibelo announced the finding on October 3, 2026, describing it as a “Full VM escape zeroday” involving “guest>host root” in industry-standard hypervisors. Vercel CEO Guillermo Rauch separately confirmed a KVM zero-day and said a full technical write-up would follow. Neither statement explained the exploit chain or identified affected versions.
KVM Zero-Day VM Escape
A bounty notification shared with the announcement shows Vercel awarding Yibelo $50,000, the program’s maximum payment for one report. The message describes the highest award as reserved for vulnerabilities that let an attacker read or change another Vercel customer’s information. Its critical category includes microVM escapes to an EC2 host and access to another customer’s data or code execution.
However, that award description should not be treated as a public demonstration of customer data theft. The screenshot hides the report’s root cause, and the available statements do not establish that real customer information was accessed.
Vercel’s $1 million Sandbox challenge opened on August 18, 2026, with a scheduled closing date of September 1. Its published rules require a live proof of concept showing a broken security boundary, rather than a report based only on reviewing code.
KVM, short for Kernel-based Virtual Machine, provides Linux virtualization. A guest virtual machine should remain separate from the host that runs it. A successful guest-to-host escape breaks that separation; root access gives an attacker the highest level of control on the host.
Vercel’s published architecture places each sandbox inside its own Firecracker microVM on a bare-metal Amazon EC2 host. Each microVM has a dedicated guest kernel, while a Linux container inside it runs the user’s code. Vercel explicitly identifies the microVM, not the container, as the main security boundary.
This distinction matters for AI agents that execute generated or downloaded code. Moving from a container into its guest operating system is not the same as reaching the underlying host. Yibelo’s claim describes the more serious boundary crossing, although the exact technical steps remain undisclosed.
The announcement does not identify a CVE, affected kernel releases, processor requirements, or a patch. It also does not establish whether guest administrator access is required. Rauch’s reference to KVM does not prove that every KVM deployment, Firecracker installation, or cloud provider is vulnerable. The missing details also prevent an independent assessment of exploit reliability across different host configurations.
For background, Cybersecuritynews previously covered the separate Januscape KVM vulnerability, which involved host memory corruption through nested virtualization. There is no disclosed evidence linking that issue to Yibelo’s finding, so its exploit conditions and fixes should not be applied to this report.
Until the technical disclosure arrives, operators should follow Vercel and their Linux vendors for guidance, rather than assume an unrelated patch addresses this flaw. The immediate takeaway is a confirmed vulnerability report and a claimed host-root escape, not confirmed widespread exploitation.
The promised write-up should clarify the root cause, affected systems, and available protections, allowing defenders to assess exposure without guessing. Those details will determine which deployments actually need urgent action.