Policy and restrictions
Limit activity to owned or expressly authorized accounts and data. Open-source findings must be reproduced locally, with no active production testing. No social engineering, disruption, persistence or retention of others’ sensitive data. Customer applications, unrelated third parties, examples, deprecated products and unsupported-impact reports are excluded. Publication requires written consent; confidentiality duties continue two years after disclosure.
Eligibility and submission status
First reproducible qualifying report receives precedence; shared root causes receive one award. Human-validated evidence and designated researcher identification are required. Past or present employees, contractors, sponsored-project maintainers/contributors, immediate employee relatives, relevant paid-engagement participants and assigned HackerOne staff are excluded.
The September 21, 2026 announcement explicitly opens this consolidated program to the security community. It says the separate Vercel Open Source program closed to new submissions and moved its coverage here; that predecessor is not treated as this identity.
Advertised rewards
Paid bounty. Platform bands: Low $50–$500, Medium $750–$1,750, High $2,000–$3,000, Critical $3,500–$5,500. Open-source Tier 1: $200–$500, $550–$1,000, $1,250–$5,000, $5,250–$10,000; Tier 2: $50–$200, $250–$500, $750–$2,500, $2,750–$5,000. Severity and category determine the band; bonuses and awards remain discretionary. Figures are advertisements, not individual awards.
Advertised schedules and exceptional ceilings are not individual award evidence.
Published scope snapshot
Captured 2026-10-03. Check the current policy for changes before participating.
| Asset | Type | Group / eligibility |
|---|---|---|
*.vercel.live | WILDCARD | Bounty eligible: Yes |
*.vercel.com | WILDCARD | Bounty eligible: Yes |
vercel.app | URL | Bounty eligible: Yes |
vercel.com | URL | Bounty eligible: Yes |
v0.dev | URL | Bounty eligible: Yes |
v0.app | URL | Bounty eligible: Yes |
https://github.com/vercel | SOURCE_CODE | Bounty eligible: Yes |
https://github.com/nitrojs/nitro | SOURCE_CODE | Bounty eligible: Yes |
https://github.com/nuxt/nuxt | SOURCE_CODE | Bounty eligible: Yes |
https://github.com/sveltejs/svelte | SOURCE_CODE | Bounty eligible: Yes |
https://github.com/vercel-labs/agent-skills | SOURCE_CODE | Bounty eligible: Yes |
https://github.com/vercel-labs/skills | SOURCE_CODE | Bounty eligible: Yes |
https://github.com/vercel/ai | SOURCE_CODE | Bounty eligible: Yes |
https://github.com/vercel/async-sema | SOURCE_CODE | Bounty eligible: Yes |
https://github.com/vercel/chat | SOURCE_CODE | Bounty eligible: Yes |
https://github.com/vercel/flags | SOURCE_CODE | Bounty eligible: Yes |
https://github.com/vercel/next.js | SOURCE_CODE | Bounty eligible: Yes |
https://github.com/vercel/swr | SOURCE_CODE | Bounty eligible: Yes |
https://github.com/vercel/turborepo | SOURCE_CODE | Bounty eligible: Yes |
https://github.com/vercel/vercel | SOURCE_CODE | Bounty eligible: Yes |
https://github.com/vercel/workflow | SOURCE_CODE | Bounty eligible: Yes |
https://github.com/vercel/eve | SOURCE_CODE | Bounty eligible: Yes |
https://github.com/vercel/ms | SOURCE_CODE | Bounty eligible: Yes |
Vercel sandbox | OTHER | Bounty eligible: Yes |
| Asset | Type | Group / eligibility |
|---|---|---|
*.vercel.app | WILDCARD | Bounty eligible: No |
Review limitations
- Policy displays September 22, 2026; reward page displays September 21, 2026. These are visible update dates, not a complete revision audit.
- Reviewed pages show dollar signs without an explicit ISO denomination; normalized currency and bounds remain null.
- Policy-version and reward-version archives, linked attachments, repository-specific policies and authenticated submission flow were not reviewed. The predecessor program URL was not independently verified.
- Summaries deliberately omit asset inventories and procedural testing instructions. They grant no authorization; full live terms and category-specific exclusions prevail.
Sources and provenance
- Vercel | Bounty Policy | HackerOne Vercel / HackerOne · reviewed 2026-10-03
- Vercel scope and advertised rewards Vercel / HackerOne · reviewed 2026-10-03
- Vercel public program updates Vercel / HackerOne · reviewed 2026-10-03
- Published HackerOne structured scope Vercel · reviewed 2026-10-03
Record reviewed 2026-10-03. Snapshot 53796974ace8. Open the complete JSON contract.