---
format: "aidr-story-markdown/v1"
id: "5ce1d227e5bb9295acf9babd647d44f5306d7bb832412201af54e88db24921e9"
canonical_url: "https://aidr.today/5ce1d227?lang=en"
title: "Vercel Confirms KVM 0day Allows Full VM Escape to Host Root"
lang: "en"
requested_lang: "en"
available_langs: ["en","vi"]
translation_fallback: null
fallback_fields: []
published_at: "2026-10-03T15:55:07.000Z"
category: "Infra"
topics: ["safety"]
source_urls: ["https://marketbrief.now/cybersecurity/vercel-confirms-kvm-0day-allows-full-vm-escape-to-host-root-e9f381c4","https://x.com/rauchg/status/2106402024804020657","https://x.com/PaulosYibelo/status/2106378929158135903","https://x.com/S1r1u5_/status/2106409377628647442","https://huggingnews.com/cybersecurity/vercel-confirms-kvm-0day-allows-full-vm-escape-to-host-root-e9f381c4"]
summary: "Security researchers found a flaw in a widely used Linux virtualization tool that gives a guest user a path to take over the physical hardware from within a virtual machine. Vercel confirmed the zero-day vulnerability in the Kernel-based Virtual Machine (KVM), which permits a full VM escape from guest to host root, after Paulos Yibelo and other researchers identified the issue through the company's Sandbox bounty program. The vulnerability impacts a tool described as the industry's gold standard for Linux virtualization, and experts warn that the blast radius of the bug is huge. Vercel is using the discovery to harden the sandbox environment for its AI agents and will publish a full technical writeup of the exploit."
---

# Vercel Confirms KVM 0day Allows Full VM Escape to Host Root

> [Open the canonical story](<https://aidr.today/5ce1d227?lang=en>)

**Published:** 2026-10-03T15:55:07.000Z
**Category:** Infra
**Topics:** safety

## Summary

Security researchers found a flaw in a widely used Linux virtualization tool that gives a guest user a path to take over the physical hardware from within a virtual machine\. Vercel confirmed the zero\-day vulnerability in the Kernel\-based Virtual Machine \(KVM\), which permits a full VM escape from guest to host root, after Paulos Yibelo and other researchers identified the issue through the company's Sandbox bounty program\. The vulnerability impacts a tool described as the industry's gold standard for Linux virtualization, and experts warn that the blast radius of the bug is huge\. Vercel is using the discovery to harden the sandbox environment for its AI agents and will publish a full technical writeup of the exploit\.

## Sources

- [Story source](<https://marketbrief.now/cybersecurity/vercel-confirms-kvm-0day-allows-full-vm-escape-to-host-root-e9f381c4>)
- [Story source](<https://x.com/rauchg/status/2106402024804020657>)
- [Story source](<https://x.com/PaulosYibelo/status/2106378929158135903>)
- [Supporting source](<https://x.com/S1r1u5_/status/2106409377628647442>)
- [Story source](<https://huggingnews.com/cybersecurity/vercel-confirms-kvm-0day-allows-full-vm-escape-to-host-root-e9f381c4>)

