Vercel Consolidates Private and OSS Bug Bounty Programs into Unified Public Program
Vercel has transitioned its security vulnerability reporting from a private, invite-only model to a unified public bug bounty program hosted on HackerOne. This consolidation covers all Vercel platform products and open-source projects under a single submission portal.
Verified State Diff
Impact & Verification Analysis
Security researchers and the broader cybersecurity community.
Centralizing the program simplifies the disclosure process for researchers and allows Vercel to leverage a wider pool of security talent to identify vulnerabilities across their entire product surface area.
Full Fact Overview
Vercel has officially opened its bug bounty program to the public, moving away from the previous private HackerOne program and separate OSS-specific bounty initiatives. The company has implemented new internal tooling to manage the expected increase in report volume, focusing on automated noise filtering and expedited remediation workflows. All security researchers can now submit findings for any Vercel product or open-source project through a single HackerOne dashboard, replacing the fragmented reporting structure that previously existed.