megachangelog
Announcement

Vercel OSS Bug Bounty Program Now Open to Public

Vercel has launched a public bug bounty program on HackerOne for its open source projects including Next.js, Nuxt, SWR, Svelte, and others. Security researchers can now report vulnerabilities in these widely-used frameworks and tools, with structured rewards and coordinated disclosure processes to protect the millions of developers relying on them.

Security is foundational to everything we build at Vercel. Our open source projects power millions of applications across the web, from small side projects to demanding production workloads at Fortune 500 companies. That responsibility drives us to keep investing in security for the platform and the broader ecosystem.

Today, we're opening the Vercel Open Source Software (OSS) bug bounty program to the public on . We're inviting security researchers everywhere to find vulnerabilities, challenge assumptions, and help us reduce risk for everyone building with these tools.HackerOne

Since August 2025, we've run a private bug bounty for our open source software with a small group of researchers. That program produced multiple high-severity reports across our Tier 1 projects and helped us refine our processes for triage, fixes, coordinated disclosure, and CVE publication. Now we're ready to expand.

Last fall, we opened a bug bounty program focused on and the React2Shell vulnerability class. Rather than wait for bypasses to surface in the wild, we took a proactive approach: pay security researchers to find them first.Web Application Firewall

That program paid out over $1M across dozens of researchers who helped us find and fix vulnerabilities before attackers could. The lesson was clear. Good incentives and clear communication turn researchers into partners, not adversaries.

Opening our private OSS bug bounty program to the public is the natural next step. Security vulnerabilities in these projects don't just affect Vercel; they affect everyone who builds with these tools. Finding and fixing them protects millions of end-users.

All Vercel open source projects are in scope. The projects listed below represent the core of the Vercel open source ecosystem. These are the frameworks, libraries, and tools that millions of developers rely on daily.

These are the projects where vulnerabilities have the highest potential impact, and where we prioritize incident response, vulnerability management, and CVE publication.

If you’re a security researcher and ready to start hunting, visit to find everything you need: scope details, reward ranges, and submission guidelines.HackerOne

When you find a vulnerability, submit it through HackerOne with clear reproduction steps. Our security team reviews every submission and works directly with researchers through the disclosure process. We're committed to fast response times and transparent communication.

We appreciate the researchers who take the time to dig into our code and report issues responsibly. Your work helps keep these projects safer for everyone.

or .Join our bug bounty programlearn more about security at Vercel

Read more

Building on our foundation of security investment

Which projects are covered

How to participate

Core projects included in the HackerOne program

Project

Description

Next.js

React framework for production web applications

Nuxt

Vue.js framework for modern web development

SWR

React Hooks library for data fetching

Svelte

Framework for building user interfaces

Turborepo

High-performance build system for monorepos

AI SDK

TypeScript toolkit for AI applications

vercel (CLI)

Command-line interface for Vercel platform

workflow

Durable workflow execution engine

flags

Feature flags SDK

ms

Tiny millisecond conversion utility

nitrojs

Universal server engine

async-sema

Semaphore for async operations

skills

The open agent skills tool: npx skills

securitybug-bountyopen-sourcevulnerability-disclosure

Source: original entry ↗

More from Vercel

Follow Vercel to get its new changes in your feed and email digest.

Feature

OpenAI Decisions API now available on AI Gateway

OpenAI's Decisions API is now accessible through Vercel's AI Gateway with an OpenAI-compatible endpoint, enabling decision models to answer typed questions and return probabilities, choices, and scores for routing, triage, and guardrails use cases. Support is available across the OpenAI SDK, AI SDK, HTTP API, and CLI with the latest versions.

ai-gatewayopenaiapidecisionssdks
Feature

Timestamp attributes now supported in Vercel Flags

Vercel Flags now supports timestamp attributes for entities, allowing you to create time-based targeting rules. Use this feature to run limited-time campaigns, show content between specific dates, or target users based on registration date.

flagstargetingfeaturetimestampscampaigns
Feature

Glyph Cluster now available in stealth on AI Gateway

Glyph Cluster, a reasoning model for coding and long-context analysis, is now available as a stealth model on Vercel's AI Gateway for Pro and Enterprise plan teams with purchased AI Gateway credits at no cost during the stealth period. The model supports function calling, streams responses, and can be accessed via AI SDK, OpenAI-compatible APIs, and coding agents.

ai-gatewaymodelscodingstealth
See all Vercel changes →