Vercel confirms KVM zero-day allowing full guest-to-host VM escape

Vercel's CEO confirmed a KVM zero-day reported via the Vercel Sandbox bounty program that reportedly lets guest code gain root on the host. No CVE or patch has been published yet.

Vercel confirms KVM zero-day allowing full guest-to-host VM escape

At a glance

  • Researcher Paulos Yibelo disclosed a full guest-to-host root VM escape on October 3, 2026
  • Vercel CEO Guillermo Rauch confirmed a KVM zero-day and paid a $50,000 bounty, the program maximum
  • No CVE, affected kernel versions, CVSS score or patch have been published so far
  • Operators of KVM-based platforms should watch Vercel and Linux vendor advisories for the promised write-up

Vercel has confirmed a zero-day vulnerability in KVM, the Linux kernel's built-in hypervisor, that reportedly allows code running inside a guest virtual machine to escape and gain root access on the underlying host. According to Cyber Security News, the flaw was reported by security researcher Paulos Yibelo through the Vercel Sandbox bug bounty program, and Vercel awarded him $50,000, the program's maximum payout for a single report. The disclosure matters because KVM underpins a large share of cloud and sandbox infrastructure, and a working guest-to-host escape breaks the main isolation boundary between untrusted code and the host.

What happened

Yibelo announced the finding publicly on October 3, 2026, describing it as a full VM escape zero-day giving guest-to-host root in industry-standard hypervisors, Cyber Security News reported. Vercel CEO Guillermo Rauch separately confirmed that the company had verified a KVM zero-day through its sandbox bounty program, calling KVM the industry's gold standard for Linux virtualization, and said a full technical write-up would follow.

According to Tech Insider, the bounty program is managed through HackerOne. Neither the researcher nor Vercel has said when the issue was first reported privately.

Technical details

Very little is known so far. Both outlets note that the announcements do not identify a CVE, a CVSS score, affected kernel releases, processor requirements or a patch. Tech Insider writes that it remains unclear whether the flaw lies in device emulation, memory handling or kernel code, and whether there has been any exploitation in production.

Vercel's published architecture, as described by Cyber Security News, runs each sandbox inside its own Firecracker microVM on a bare-metal Amazon EC2 host, with a dedicated guest kernel and a Linux container inside each microVM. Vercel identifies the microVM, not the container, as the primary security boundary, which is why an escape from the guest to the host is rated at the top of its bounty scale.

Who is affected

The exact scope is unconfirmed. Because KVM is the hypervisor behind many Linux virtualization and microVM platforms, the issue could be relevant well beyond Vercel. Tech Insider notes that it is not yet known whether other Firecracker-based platforms share the exposure; that question remains open until technical details are released.

What to do

There is no fix to apply yet. Cyber Security News advises operators to follow Vercel and their Linux vendors for guidance until the technical disclosure arrives, rather than assume that an unrelated kernel patch addresses this flaw. Organizations running multi-tenant workloads or untrusted code on KVM should subscribe to their distribution's and cloud provider's security bulletins, keep host kernels on a fast patch cycle, and review defense-in-depth controls on hypervisor hosts, such as limiting host-side services and monitoring for unexpected privileged processes.

Sources

This story is based on the sources listed above. Always check the vendor’s official advisory before acting on critical systems.