Skip to main content

The Vercel Bug Bounty Program is now publicly available

By Steven Van ·

Vercel folds its private HackerOne program and its open-source bounty program into one public program covering the whole platform.

Vercel has merged its private HackerOne bug bounty program, running since 2022, with its open-source bug bounty program into a single public bug bounty program for Vercel.

The company says AI has sharply increased the volume of both valid and invalid vulnerability reports industry-wide. While some companies have responded by moving to private programs, Vercel says public reports were still surfacing real findings, so it built tooling to filter out noise and speed up triage and remediation ahead of the public launch.

  • All products across the Vercel platform, plus its open-source projects, are now covered under the one program, with full scope listed on HackerOne.
  • New vulnerability reports for Vercel's open-source projects should now go to the main Vercel program.
  • Submissions already made through the previous OSS program do not need to be resubmitted; Vercel says it will still review them.
Vercel
Vercel
The platform for frontend developers — deploy, preview, and scale web apps and AI agents with zero config.
View Vercel →

Read the original announcement →

Read The Vercel Bug Bounty Program is now publicly available on Creators Toolbox