Feed
Bounty Rolling

Vercel Open Source Software Bug Bounty Program

Vercel pays security researchers for vulnerabilities in its open source projects such as Next.js, Turborepo and the AI SDK through a public bug bounty on HackerOne. Open with no deadline.

The Vercel Open Source Software Bug Bounty Program rewards security researchers who find vulnerabilities in Vercel's open source projects. Vercel opened the program to the public on HackerOne on February 3, 2026. It has no deadline.

All Vercel open source projects are in scope. The announcement lists 13 core projects, including Next.js, Nuxt, SWR, Svelte, Turborepo, the AI SDK, the Vercel CLI, workflow, flags, ms, nitrojs, async-sema and skills.

Researchers submit reports through HackerOne with clear reproduction steps. Vercel's security team reviews each report and manages the disclosure process. Reward ranges are published on the HackerOne program page and are not stated in the announcement.

Vercel says its earlier bug bounty for its web application firewall paid out more than $1 million to dozens of researchers. The new program invites security researchers everywhere to report issues responsibly.

Source · vercel.com/blog/the-vercel-oss-bug-bounty-program-is-now-available Published 3 February 2026 · Added here 14 September 2026