AIO APEX

Vercel confirms KVM zero-day that lets sandbox code escape to host root

Cybersecurity News
Share:
Vercel confirms KVM zero-day that lets sandbox code escape to host root

Vercel has confirmed a zero-day vulnerability in KVM, the Linux kernel’s virtualization module, after a security researcher showed that code inside a guest virtual machine could gain root access on the host. The finding came through Vercel’s Sandbox bug bounty program, which paid the researcher $50,000, the maximum the program allows for a single report.

The bug matters because sandboxes that run untrusted code rely on KVM as their final isolation layer. Vercel runs each sandbox inside its own Firecracker microVM, a lightweight virtual machine built on KVM, so the microVM boundary is the main barrier between user code and the host. A guest-to-host escape goes straight through that barrier. Vercel positions its sandboxes as a place to run AI agent code, which makes the risk relevant to any workload that executes model-generated code there.

Researcher Paulos Yibelo announced the finding on October 3, describing a full VM escape that gives a guest root access on the host in standard hypervisors. Vercel CEO Guillermo Rauch then confirmed the vulnerability in a post on X, calling it a KVM 0day affecting “the industry’s gold standard solution for Linux virtualization” and promising a full technical write-up. Cybersecurity News first reported the bounty and the confirmation.

Several details are still missing. Vercel’s statement does not name a CVE, the affected kernel versions, the processor types involved, or a patch. Operators can’t yet tell whether their hosts are exposed or whether their Linux distribution already ships a fix. Teams running their own KVM hosts should watch their kernel vendor’s security advisories and check their configuration against the affected code path once the write-up is out.

The bounty size is a useful signal in itself. A program paying its ceiling for a hypervisor escape shows how seriously the industry now treats isolation bugs in agent sandboxes. The write-up will show whether this is a narrow KVM flaw or a broader class of problem that affects other sandbox designs too.

Originally reported by Cybersecurity News. Read the original article for additional details.

View original source
Share: