The Vercel Bug Bounty Program is now publicly available

Vercel combines its private and open-source bug bounty programs into a single public program hosted on HackerOne. The unified initiative covers all platform products and open-source projects, incorporating streamlined triage processes and tooling to manage vulnerability reports and remediation.

Cover image for The Vercel Bug Bounty Program is now publicly available

In 2022 Vercel started a private bug bounty program on HackerOne and later added several public challenges, each offering a $1 million reward. The company has now merged its private and open‑source initiatives into a single public program that runs on HackerOne and covers every product and open‑source project. AI has dramatically increased the volume of vulnerability reports, prompting many firms to retreat to private programs, but Vercel found that public submissions continue to yield valuable discoveries. By unifying the scopes, the company aims to reduce confusion for researchers and streamline triage, filtering noise and accelerating remediation across the whole platform. It remains uncertain how the influx of AI‑generated reports will affect the overall quality of findings once the public program scales. Vercel’s security team claims the new tooling will handle the load, but independent verification of that capability has not been presented.