The Vercel OSS Bug Bounty program is now available
By Steven Van ·
The public program covers Next.js, Nuxt, Svelte and other Vercel open source projects, building on a private beta running since August 2025.
Vercel has opened its Open Source Software bug bounty program to the public on HackerOne, inviting security researchers to find and report vulnerabilities in projects including Next.js, Nuxt, SWR, Svelte, Turborepo, and the AI SDK.
The program ran privately since August 2025 with a small group of researchers, producing multiple high-severity reports across Vercel's Tier 1 projects and helping refine its triage, fix, disclosure, and CVE processes. It builds on a separate bounty opened last autumn for Vercel's Web Application Firewall and the React2Shell vulnerability class, which paid out more than $1M to researchers who found and fixed vulnerabilities before attackers could.
