60 بالعربي

Researcher Discloses Zero-Day Vulnerability in KVM Enabling Virtual Machine Escape, Vercel Pays $50k Reward

A researcher disclosed a KVM zero-day allowing escape from a virtual machine to root on the host server; Vercel confirmed it and paid $50,000.

October 4, 2026
Researcher Discloses Zero-Day Vulnerability in KVM Enabling Virtual Machine Escape, Vercel Pays $50k Reward
Audio available in Arabic

Listen to this story

0:00
1:02

Researcher Paulos Yibelo disclosed a zero-day security vulnerability in the KVM system that enables a complete virtual machine escape and access to root privileges on the host server, after discovering it through the Vercel Sandbox bug bounty program. Guillermo Rauch, CEO of Vercel, confirmed the existence of the vulnerability, and the company paid the researcher the maximum single-report bounty of $50,000.

The Vercel Sandbox platform runs untrusted workloads, including AI agent code, inside Firecracker microVMs running on bare-metal EC2 servers. The microVM serves as the primary security boundary separating customer code from one another and from the platform infrastructure.

To date, no CVE identifier, security update, or list of affected versions has been published, and there is no evidence of active exploitation of the vulnerability or customer data leakage. This uncertainty in the scope of impact dictates the extent of follow-up required by technical teams relying on isolated environments to execute code.

The incident is of particular importance in the artificial intelligence field, as agent execution tools rely on the same isolation technologies to keep untrusted code contained away from core systems. The successful VM escape demonstrates that security boundaries assumed to be solid are penetrable, bringing the testing of these environments back to the forefront of developers' priorities.

What do these terms mean?

KVM: A virtualization technology built into the Linux system that allows running multiple operating systems on a single server. Zero-Day Vulnerability: A security flaw previously unknown to the developer, exploited before a fix is released. MicroVM: A lightweight and fast version of a virtual machine used to isolate a single workload. Root Privileges: The highest level of permission in the system, giving whoever obtains it complete control.

Share
Keywords