Eigen RadarAI
Analysis

Vercel confirms KVM flaw reported through its Sandbox program

Vercel has confirmed a KVM vulnerability reported through its Sandbox bounty program. Researcher Paulos Yibelo says it permits an escape from a guest virtual machine to root access on the host. The confirmation and reported $50,000 award do not establish customer-data theft. A technical write-up is pending, with affected versions, required privileges and remediation still unspecified.

Artificial Intelligence··Evening
A technician seen from behind works on an open server sled at a maintenance bench between data-centre racks.

A KVM flaw validated through the bounty program

Vercel has confirmed a KVM zero-day reported through its Sandbox bounty program. Researcher Paulos Yibelo describes an escape from a guest virtual machine to root access on its host. Vercel's confirmation concerns the reported vulnerability; a full technical account of the escape and its affected systems has not yet been released.[1], [2]

Yibelo and Vercel chief executive Guillermo Rauch made their public statements on October 3. Rauch said a full write-up would follow. Cyber Security News reported the confirmation the next day and described a bounty notification showing a $50,000 award, identified as the program's maximum payment for one finding. The award category covers breaches of customer isolation, including possible access to another customer's data or code execution. Access to another customer is among the category's severe breach criteria. Actual theft of customer information has not been confirmed, and validation of the vulnerability does not establish such a theft.[1]

The virtual machine separates code from the host

Vercel Sandbox runs workloads in Firecracker microVMs on bare-metal Amazon EC2 hosts. Each microVM has its own guest kernel, with a Linux container inside it running the user's code. The company identifies the microVM as the main security boundary, rather than the inner container. An escape from that container into the guest operating system differs from an escape out of the guest into the host. Yibelo's claim concerns the latter boundary. This infrastructure contains untrusted workloads and code run by AI agents. The claimed root access is on the host outside the guest operating system, rather than a separate container-only escape.[1]

Affected versions and remediation remain unspecified

The public disclosure does not identify a CVE number, affected kernel versions, processor requirements or an available patch. It leaves unclear whether exploiting the finding requires administrative privileges within the guest. Rauch's reference to KVM does not establish that every KVM deployment or every Firecracker installation is vulnerable. It also does not show that other cloud providers are affected. Neither statement discloses the exploit chain, and no connection has been established with a separate KVM flaw covered in earlier reporting. The precise scope and remediation remain subjects of the promised technical disclosure.[1]

References

  1. News sourceCyber Security NewsVercel confirms a KVM flaw reported through its agent-sandbox bounty program↩1↩2↩3↩4
  2. News sourceexplainx.aiVercel Confirms a KVM Zero-Day VM Escape: What It Means for Agent Sandboxes↩