Vercel Confirms KVM Zero-Day VM Escape, Awards Researcher $50,000
Vercel has confirmed a critical KVM zero-day vulnerability, allowing a guest virtual machine to achieve root access on the host, following a report from security researcher Paulos Yibelo.

Vercel has confirmed a significant KVM zero-day vulnerability that allows a guest virtual machine to gain root access on the host system. The discovery was made by security researcher Paulos Yibelo, who reported the "Full VM escape zeroday" through Vercel's Sandbox bug bounty program. This finding raises serious concerns about the security of virtualized environments, particularly those used to contain untrusted code and AI agents.
Yibelo announced the vulnerability on October 3, 2026, describing it as a "guest>host root" escape in industry-standard hypervisors. Vercel CEO Guillermo Rauch corroborated the existence of the KVM zero-day, promising a detailed technical write-up in the future. While the exact exploit chain and affected versions remain undisclosed, Vercel awarded Yibelo the maximum bounty of $50,000 for the report, indicating its critical severity.
The vulnerability was discovered within Vercel's sandbox environment, which is designed to isolate untrusted workloads. Vercel's architecture typically places each sandbox within a Firecracker microVM running on a bare-metal Amazon EC2 host. The microVM itself serves as the primary security boundary, with a Linux container inside executing the user's code. A successful guest-to-host escape, as claimed by Yibelo, represents a breach of this fundamental isolation.
While the exact technical details are still pending, the implications of a VM escape are profound. Gaining root access on the host system allows an attacker the highest level of control, potentially enabling them to compromise other virtual machines, access sensitive data, or disrupt the underlying infrastructure. The bug bounty award description suggests that vulnerabilities allowing access to another customer's data or code execution fall into the critical category.
It is important to note that the specific technical details, including the root cause, affected kernel releases, and processor requirements, have not yet been publicly disclosed. Vercel's confirmation and the bounty awarded highlight the severity, but without a full technical write-up, it is difficult to assess the exploit's reliability across different configurations or determine which specific KVM deployments are vulnerable.
This incident is distinct from previously reported KVM vulnerabilities, such as the Januscape vulnerability, and no evidence suggests a link between them. Defenders are advised to await official guidance from Vercel and their Linux vendors rather than assuming unrelated patches will mitigate this specific flaw.
The immediate takeaway is the confirmation of a critical zero-day vulnerability and a claimed host-root escape. The promised technical disclosure from Vercel will be crucial for understanding the precise nature of the vulnerability, the scope of affected systems, and the necessary protective measures. Until then, organizations relying on KVM virtualization should remain vigilant and monitor official communications for updates.