Vercel Sandbox Opens $1M Security Challenge
Vercel launched a two-week HackerOne program offering up to $50,000 per report for vulnerabilities that escape its Firecracker microVM or host-side network controls. The challenge targets flaws capable of exposing or modifying another tenant’s data.
This is a smart stress test for the infrastructure layer AI agents increasingly depend on, where isolation failures can turn generated code into a cloud-wide breach.
- –Researchers must demonstrate a live boundary break, not merely submit static analysis
- –The challenge explicitly tests both Firecracker isolation and host-side networking
- –Up to $1 million in total payouts signals how seriously Vercel views agent execution security
- –Findings could improve sandbox designs across coding agents, code runners, and untrusted workload platforms
DISCOVERED
46d ago
2026-08-18
PUBLISHED
46d ago
2026-08-18
RELEVANCE
AUTHOR
vercel