Vercel unveils open source software (OSS) bug bounty program
Key point
Vercel has unveiled an open source software (OSS) bug bounty program through HackerOne to help uncover security vulnerabilities.
Details
Vercel has publicly launched an open source software (OSS) bug bounty program through HackerOne. The goal is to help security researchers find vulnerabilities in Vercel's open source projects and reduce risk.
Since August 2025, Vercel has run a private program with a small group of researchers, refining processes for vulnerability triage, fixes, and CVE disclosure. Additionally, last fall, Vercel ran a proactive rewards program in response to Web Application Firewall (WAF) and React2Shell vulnerabilities, paying out more than $1 million in rewards to dozens of researchers to strengthen security.
The scope of this program covers all core projects in the Vercel ecosystem. Key targets include:
- Next.js, Nuxt, Svelte (frameworks)
- SWR, AI SDK, Turborepo (libraries and tools)
- Vercel CLI, workflow, flags, nitrojs, and more
Security researchers can submit vulnerability reports with reproduction steps via HackerOne, and Vercel's security team has pledged prompt response and transparent communication.
This summary was generated automatically by AI. Check the original for the author's claims and context. Copyright belongs to the original author.
Our guide explains how the AI works. Report summary errors, attribution issues, or removal requests via Contact.