
Vercel confirms KVM zero-day that lets sandbox code escape to host root
A researcher reported a full VM escape in KVM, the virtualization layer Vercel’s sandboxes rely on. Vercel paid $50,000, the program’s maximum, and no CVE or patch has been published yet.









