Vercel’s focused sandbox security challenge generated 1,285 submissions during a two-week testing window that ran from August 18 to September 1. According to results reported by SecurityWeek, the company had validated one critical, seven high, 15 medium and 49 low-severity findings while triage continued.
The most consequential report combined two Linux networking-stack defects: one could expose host-kernel memory and another could crash the host. Technical details remain private while fixes are reviewed and CVE identifiers are pending. Vercel said none of the submissions demonstrated access to real customer data.
The volume also changed the triage process. Vercel moved from a separate human-reviewed chat for each report to an agent-assisted workflow that checks policy, searches for duplicates and runs proofs of concept in a sandbox. The company says it plans to open-source that triage tooling.
Why it matters
The exercise shows how AI-assisted vulnerability research can increase both useful findings and operational noise. Providers running untrusted code need isolation controls, but they also need evidence-driven triage that can keep pace without treating every automated report as a confirmed escape.
For wider context, see SectechMedia’s related technical coverage.
