# Vercel Confirms KVM Zero-Day Guest-to-Host VM Escape (Root on Host) via Sandbox Bug Bounty; $50,000 Bounty Awarded

> Researcher Paulos Yibelo reported a KVM zero-day enabling full guest-to-host VM escape with root on the host through Vercel's Sandbox bug bounty; Vercel CEO Guillermo Rauch confirmed it and paid the $50,000 maximum. No CVE, affected versions, patch status or exploit details have been disclosed, and there is no evidence of in-the-wild exploitation.

- **Published:** 2026-10-04T00:00:00Z
- **Last reviewed:** 2026-10-04T00:00:00Z
- **Canonical:** https://intel.threadlinqs.com/threat/TL-2026-2878
- **ID:** TL-2026-2878
- **Severity:** HIGH
- **Category:** ZERO_DAY
- **Status:** TRACKING
- **Detections:** 9 · **IOCs:** 11 (full data via the Threadlinqs MCP server — Purple tier)

## Description

On 2026-10-03 security researcher Paulos Yibelo announced on X a 'Full VM escape zeroday (guest>host root in industry standard hypervisors)'. Vercel CEO Guillermo Rauch confirmed on X that Vercel had 'confirmed a KVM 0day through our Vercel Sandbox bounty program', described KVM as the industry's gold-standard Linux virtualization solution, thanked Yibelo and other researchers, and said a full write-up is coming. Cyber Security News (2026-10-04) reports that Vercel awarded Yibelo $50,000, the maximum payment for a single report.

The finding came from Vercel's public HackerOne Sandbox program (open 2026-08-18 to a scheduled close of 2026-09-01, up to $1,000,000 total pool, up to $50,000 per report). Per Vercel's challenge page, every Vercel Sandbox runs in its own Firecracker microVM with a dedicated guest kernel on bare-metal EC2 hosts; the microVM, not the inner Linux container, is the security boundary. In scope were escapes from Firecracker to the EC2 host, cross-tenant read/modify/execute/crash through the compute layer, and defeating the host-side network firewall. Reports required a live proof-of-concept, so the escape was demonstrated to Vercel, but no technical details have been released.

Undisclosed as of publication: CVE identifier, CVSS, affected kernel versions, CPU vendor/architecture requirements, whether it is a Linux kernel KVM bug or lies in a different component, patch availability, and whether any customer data was exposed. This record therefore does not infer specifics. Commentators (e.g. @s1r1u5_) warned the blast radius could be large, which is opinion, not evidence.

Context, not established as related: in July 2026 a separate 16-year-old Linux KVM shadow-MMU use-after-free dubbed Januscape (CVE-2026-53359, companion CVE-2026-46113, found by Hyunwoo Kim via Google kvmCTF) was disclosed; it requires root in a guest with nested virtualization enabled and was fixed in stable kernels on 2026-07-04. Cyber Security News notes no confirmed link between Januscape and the Vercel finding, and the CSA note on Januscape does not mention Vercel. Defenders should watch for the promised Vercel write-up and any CVE assignment before treating the two as the same bug.

Defensive takeaway: guest-to-host escape on multi-tenant sandbox, CI/CD and AI-agent execution platforms breaks tenant isolation. Until details are published, prioritize hypervisor/kernel patch hygiene, restrict nested virtualization and /dev/kvm exposure where not required, monitor host-side telemetry for unexpected processes spawned by VMM (e.g. Firecracker/QEMU) processes, and subscribe to Vercel, kernel.org KVM and distro security advisories.

## MITRE ATT&CK

- T1078 Valid Accounts
- T1059 Command and Scripting Interpreter
- T1611 Escape to Host
- T1005 Data from Local System

## Sources

- [Vercel Confirms KVM Zero-Day VM Escape, Awards Researcher $50,000](https://cybersecuritynews.com/kvm-zero-day-vm-escape/)
- [Guillermo Rauch (@rauchg) on X: confirmed a KVM 0day through the Vercel Sandbox bounty program](https://x.com/rauchg/status/2106402024804020657)
- [Vercel Confirms KVM 0day Allows Full VM Escape to Host Root](https://huggingnews.com/cybersecurity/vercel-confirms-kvm-0day-allows-full-vm-escape-to-host-root-e9f381c4)
- [$1 million hacker challenge for Vercel Sandbox](https://vercel.com/blog/one-million-dollar-hacker-challenge-for-vercel-sandbox)
- [Vercel Sandbox bug bounty program (HackerOne)](https://hackerone.com/vercel_sandbox)
- [This company wants you to break out of its security sandbox - and there's $1 million up for grabs (ITPro)](https://itpro.com/security/this-company-wants-you-to-break-out-of-its-security-sandbox-and-theres-usd1-million-up-for-grabs)
- [Januscape: 16-Year-Old Linux KVM Flaw Lets Guest Escape to Host (The Hacker News) - related context, not confirmed linked](https://thehackernews.com/2026/07/16-year-old-linux-kvm-flaw-lets-guest.html)
- [CSA Research Note: Januscape KVM Guest-to-Host Escape (CVE-2026-53359) - related context](https://labs.cloudsecurityalliance.org/research/csa-research-note-januscape-kvm-guest-host-escape-cve-2026-5/)

## Full data

Detection queries (Splunk SPL / Microsoft KQL / Sigma) and IOC values require the Threadlinqs MCP server (Purple tier): https://intel.threadlinqs.com/mcp

Canonical: https://intel.threadlinqs.com/threat/TL-2026-2878
