Vercel Launches Unified Public Bug Bounty Program on HackerOne
Key point
The new program covers all Vercel products and open-source projects, consolidating previous private and OSS initiatives.
Details
Vercel has combined its private bug bounty program and open-source security initiatives into a single, public program hosted on HackerOne. This consolidation covers all products across the Vercel platform and its open-source projects, simplifying the disclosure process for researchers who previously had to navigate multiple submission channels.
Why Vercel Went Public
The decision to go public follows years of operating a private program via HackerOne’s VIP tier, which onboarded thousands of researchers and hardened the platform. Vercel notes that AI has exponentially increased the volume of bug reports, both valid and invalid. While some companies retreated to private programs to manage this noise, Vercel found that public reports continued to surface valuable findings. The company believes AI enables a wider range of researchers to discover vulnerabilities and chose to evaluate reports on their own merit.
To handle the increased volume, Vercel’s security engineering team streamlined processes and built tooling to filter noise and expedite remediation. The team states that their processes have been battle-tested through previous large public challenges, such as the $1 million React2Shell and $1 million Vercel Sandbox hacker challenges.
Participation Details
Researchers can now submit findings for all Vercel products and OSS projects through the main HackerOne program page. Previous submissions to the separate OSS program do not need to be copied over; Vercel will continue to review those existing reports. The company emphasizes fast response times and transparent communication throughout the disclosure process.
This summary was generated automatically by AI. Check the original for the author's claims and context. Copyright belongs to the original author.
Our guide explains how the AI works. Report summary errors, attribution issues, or removal requests via Contact.