ZERO-DAY

Vercel confirms a KVM zero-day: guest-to-host root, and nothing to patch yet

Vercel CEO Guillermo Rauch says the company has confirmed a KVM zero-day reported through its Vercel Sandbox bug bounty. The researcher, Paulos Yibelo, describes it as a full VM escape: code in a guest gets root on the host. Vercel paid $50,000, the top award in that program. CVE, affected kernel versions, root cause and patch: Undisclosed. No in-the-wild exploitation has been reported. A full write-up is promised.

Oct 5, 2026 · 3 min read

KVM sits under most Linux clouds, most Firecracker microVM sandboxes and a lot of the infrastructure that now runs AI agent code. When the hypervisor boundary is the thing that keeps one tenant out of another, a confirmed guest-to-host escape matters even before anyone publishes a line of exploit detail.

What’s confirmed. On Oct 3, Rauch posted on X: “We’ve confirmed a KVM 0day through our Vercel Sandbox bounty program,” adding that a full write-up is coming. Yibelo posted the same day, calling it a “full VM escape zeroday (guest>host root in industry standard hypervisors).” Per Cybernews and Cybersecuritynews, the bounty notice he shared puts the report in Vercel’s critical tier, which covers microVM escapes to the EC2 host and cross-customer access. That tier description is the program’s category, not proof that any real customer data was touched.

What isn’t. No CVE, no CVSS, no affected kernel releases, no CPU requirements, no patch, and no word on whether the guest needs root first. Rauch naming KVM doesn’t establish that every KVM host, every Firecracker deployment or every hyperscaler is exposed. It’s also not the separate Januscape KVM escape disclosed earlier, and nothing published so far says the Januscape fix covers this one.

Why the architecture matters. Vercel’s published design runs each sandbox in its own Firecracker microVM on bare-metal EC2, with the user’s code in a container inside the guest. Vercel treats the microVM, not the container, as the real wall. Yibelo’s claim is that he got through that wall to the host. That’s the scenario multi-tenant sandbox, CI runner and agent-hosting platforms are built to rule out.

What we’d do this morning. List every place you run code you didn’t write inside KVM guests: agent sandboxes, CI runners, notebook and eval clusters, customer plugin hosts. Note which ones share a physical host across tenants or trust levels. Those are the ones to move toward dedicated hosts or tighter scheduling if the write-up lands badly. Confirm the VMM side is still locked down (Firecracker’s jailer and seccomp filters on, VMM running unprivileged), because that’s your second layer if the guest-to-host boundary goes. Make sure host kernel oops and KVM warnings, plus unexpected child processes or file writes from the VMM process, actually reach your SIEM. Then watch your distro and cloud provider advisories, not just Vercel’s blog.

The market read. Agent sandboxes are turning into a security product category of their own, and isolation strength is the pitch. A public host-escape bounty is a good look for Vercel’s program and a pointed question for every sandbox vendor selling “safe to run anything.” The $50K payout already has researchers arguing that hypervisor-grade bugs are underpriced.

Desk sheet: Rauch on X (Oct 3): KVM 0-day confirmed via Vercel Sandbox bounty; write-up pending. Yibelo on X (Oct 3): guest-to-host root. Bounty: $50,000. CVE, versions, root cause, patch: Undisclosed. In-the-wild exploitation: none reported.

Sources