vulns.co
/
GKData.io MCP

Vercel · 3 min read

Vercel Bug Bounty

Vercel · HackerOne. Policy reviewed 2026-10-03. Live terms govern participation.

Open current policy Reviewed policy

Policy and restrictions

Limit activity to owned or expressly authorized accounts and data. Open-source findings must be reproduced locally, with no active production testing. No social engineering, disruption, persistence or retention of others’ sensitive data. Customer applications, unrelated third parties, examples, deprecated products and unsupported-impact reports are excluded. Publication requires written consent; confidentiality duties continue two years after disclosure.

Eligibility and submission status

First reproducible qualifying report receives precedence; shared root causes receive one award. Human-validated evidence and designated researcher identification are required. Past or present employees, contractors, sponsored-project maintainers/contributors, immediate employee relatives, relevant paid-engagement participants and assigned HackerOne staff are excluded.

The September 21, 2026 announcement explicitly opens this consolidated program to the security community. It says the separate Vercel Open Source program closed to new submissions and moved its coverage here; that predecessor is not treated as this identity.

Advertised rewards

Paid bounty. Platform bands: Low $50–$500, Medium $750–$1,750, High $2,000–$3,000, Critical $3,500–$5,500. Open-source Tier 1: $200–$500, $550–$1,000, $1,250–$5,000, $5,250–$10,000; Tier 2: $50–$200, $250–$500, $750–$2,500, $2,750–$5,000. Severity and category determine the band; bonuses and awards remain discretionary. Figures are advertisements, not individual awards.

Advertised schedules and exceptional ceilings are not individual award evidence.

Published scope snapshot

Captured 2026-10-03. Check the current policy for changes before participating.

In scope · 24 published rows
AssetTypeGroup / eligibility
*.vercel.liveWILDCARDBounty eligible: Yes
*.vercel.comWILDCARDBounty eligible: Yes
vercel.appURLBounty eligible: Yes
vercel.comURLBounty eligible: Yes
v0.devURLBounty eligible: Yes
v0.appURLBounty eligible: Yes
https://github.com/vercelSOURCE_CODEBounty eligible: Yes
https://github.com/nitrojs/nitroSOURCE_CODEBounty eligible: Yes
https://github.com/nuxt/nuxtSOURCE_CODEBounty eligible: Yes
https://github.com/sveltejs/svelteSOURCE_CODEBounty eligible: Yes
https://github.com/vercel-labs/agent-skillsSOURCE_CODEBounty eligible: Yes
https://github.com/vercel-labs/skillsSOURCE_CODEBounty eligible: Yes
https://github.com/vercel/aiSOURCE_CODEBounty eligible: Yes
https://github.com/vercel/async-semaSOURCE_CODEBounty eligible: Yes
https://github.com/vercel/chatSOURCE_CODEBounty eligible: Yes
https://github.com/vercel/flagsSOURCE_CODEBounty eligible: Yes
https://github.com/vercel/next.jsSOURCE_CODEBounty eligible: Yes
https://github.com/vercel/swrSOURCE_CODEBounty eligible: Yes
https://github.com/vercel/turborepoSOURCE_CODEBounty eligible: Yes
https://github.com/vercel/vercelSOURCE_CODEBounty eligible: Yes
https://github.com/vercel/workflowSOURCE_CODEBounty eligible: Yes
https://github.com/vercel/eveSOURCE_CODEBounty eligible: Yes
https://github.com/vercel/msSOURCE_CODEBounty eligible: Yes
Vercel sandboxOTHERBounty eligible: Yes
Out of scope · 1 published rows
AssetTypeGroup / eligibility
*.vercel.appWILDCARDBounty eligible: No

Review limitations

  • Policy displays September 22, 2026; reward page displays September 21, 2026. These are visible update dates, not a complete revision audit.
  • Reviewed pages show dollar signs without an explicit ISO denomination; normalized currency and bounds remain null.
  • Policy-version and reward-version archives, linked attachments, repository-specific policies and authenticated submission flow were not reviewed. The predecessor program URL was not independently verified.
  • Summaries deliberately omit asset inventories and procedural testing instructions. They grant no authorization; full live terms and category-specific exclusions prevail.

Sources and provenance

  1. Vercel | Bounty Policy | HackerOne Vercel / HackerOne · reviewed 2026-10-03
  2. Vercel scope and advertised rewards Vercel / HackerOne · reviewed 2026-10-03
  3. Vercel public program updates Vercel / HackerOne · reviewed 2026-10-03
  4. Published HackerOne structured scope Vercel · reviewed 2026-10-03

Record reviewed 2026-10-03. Snapshot 53796974ace8. Open the complete JSON contract.

GitHub snapshot 2026-10-04

53796974ace8 · JSON exports & schemas · CC BY 4.0 content / MIT software