A public bounty for the open source stack
Vercel has opened its Open Source Software (OSS) bug bounty program to the public on HackerOne. The program invites security researchers to probe the company's open source projects, which collectively underpin a significant portion of the web's infrastructure.
The move follows a private beta phase that ran since August 2025. During that period, a small group of researchers delivered multiple high-severity findings across Vercel's Tier 1 projects. More importantly, the private run allowed Vercel to refine its internal workflows for triage, patch development, coordinated disclosure, and CVE publication before scaling the program outward.
An extension of prior security work
This is not Vercel's first foray into crowdsourced security. Last fall, the company launched a bounty program targeting its Web Application Firewall and the React2Shell vulnerability class. The strategy there was proactive: pay researchers to discover bypasses before they could be exploited in the wild.
That initiative paid out over $1M across dozens of researchers and proved the value of aligning incentives with the security community. The lesson, according to Vercel, was that clear communication and proper rewards transform researchers into collaborative partners rather than adversaries.
The public OSS bounty now extends that approach to the company's development tools. Vulnerabilities in these projects have a reach that extends far beyond Vercel's own platform; anyone building with these frameworks and libraries is potentially exposed. Fixing those issues upstream protects a vast number of end-users across the ecosystem.
Scope and participation
All Vercel open source projects are in scope for the public program. The primary focus, however, is on the core ecosystem—the frameworks, libraries, and tools that millions of developers depend on daily. These Tier 1 projects are where vulnerability impact is highest, and consequently where Vercel prioritizes incident response, vulnerability management, and CVE publication.
Project | Description |
|---|---|
React framework for production web applications | |
Vue.js framework for modern web development | |
React Hooks library for data fetching | |
Framework for building user interfaces | |
High-performance build system for monorepos | |
TypeScript toolkit for AI applications | |
Command-line interface for Vercel platform | |
Durable workflow execution engine | |
Feature flags SDK | |
Tiny millisecond conversion utility | |
Universal server engine | |
Semaphore for async operations | |
The open agent skills tool: npx skills |
Security researchers interested in participating can visit the HackerOne page for full details on scope, reward ranges, and submission guidelines. Submissions should include clear reproduction steps. Vercel's security team reviews each report and coordinates directly with the researcher through disclosure.



