Vercel Platform Protection is taking a break and is not accepting new submissions.

Program highlights

Platform StandardsFully compliant with Platform Standards. 
Managed by HackerOneCollaboration EnabledIncludes Retesting
N/A
Average time to first response
1 month, 2 weeks
Average time to triage
N/A
Average time to bounty
1 month, 2 weeks
Average time from submission to bounty
N/A
Average time to resolution

Rewards summary

Last updated on December 6, 2025. View changes
Each severity lists the 90-day average bounty and the percentage of total resolved reports, if applicable.

Asset

Low

0% submissions

Medium

0% submissions

High

0% submissions

Critical

100% submissions

Asset

Low

0% submissions

Medium

0% submissions

High

0% submissions

Critical

100% submissions

Vercel Platform Protection
$25,000
$50,000

Scope exclusions

Core Ineligible Findings are out of scope. Learn more 

Overview

Last updated on December 6, 2025. View changes
Vercel is looking for valid reports which demonstrate a successful bypass of Vercel WAF rules, allowing for exploitation of React2Shell (CVE-2025-55182, 2025-66478).

Disclosure Policy

We are making this public program available for responsible disclosure of critical WAF workarounds on the Vercel platform. Please do not discuss these vulnerabilities (even resolved ones) outside of the program without express consent from Vercel. Follow HackerOne's disclosure guidelines.

Scope and Rewards

Successful exploitations of React2Shell (CVE-2025-55182, 2025-66478) to bypass Vercel's WAF only. An application has been setup for this purpose - only conduct testing here: https://nextjs-cve-hackerone.vercel.app/
Please Note: This program will only issue rewards for valid critical vulnerabilities that fall within the scope of the specified CVE. Any submissions that do not relate to this CVE, or that do not meet the criteria for a critical vulnerability, will be redirected to our other program. Those submissions will be evaluated according to our standard program policies and guidelines.

Program Rules

  • Provide detailed reports with reproducible steps. Reports not detailed enough to reproduce the issue will not be eligible for a reward.
  • A testing environment is provided containing a secret behind Vercel's current WAF rules in the environment variable VERCEL_PLATFORM_PROTECTION. Only reports that successfully retrieve this secret will be accepted.
  • Do NOT submit vulnerabilities that do not demonstrate a successful bypass of Vercel's WAF rules and allow for successful execution of CVE-2025-55182.
  • If you find a valid vulnerability unrelated to this scope, submit it to responsible.disclosure@vercel.com instead.
  • Submit one vulnerability per report, unless chaining is required to demonstrate impact.
  • When duplicates occur, only the first valid, reproducible report is awarded.
  • Multiple vulnerabilities caused by a single root cause will receive one bounty.
  • Social engineering (phishing, vishing, smishing) is prohibited.
  • Make a good-faith effort to avoid privacy violations, data destruction, or degradation of service.
  • Ask the program team before submitting vulnerabilities on unscoped subdomains.
  • Only interact with accounts you own, accounts with explicit permission, or the test account provided by Vercel.

Test Plan

Demonstrate a successful attack by providing the secret within the environment variable VERCEL_PLATFORM_PROTECTION behind the testing application: https://nextjs-cve-hackerone.vercel.app/. There will be a required field for this when you submit a report.

Thank you for helping keep Vercel and our users safe!

Top hackers

1
lachlan2k
ID-verifiedHacker that has successfully completed an ID verification check.
lachlan2k
Reputation: 85
2
sy1vi3
ID-verifiedHacker that has successfully completed an ID verification check.
sy1vi3
Reputation: 85
3
hacktronresearch
Clear-verified badgeHacker that has completed both ID-verification and a background check.
hacktronresearch
Reputation: 57
4
maple3142
maple3142
Reputation: 48
5
ryotak
Clear-verified badgeHacker that has completed both ID-verification and a background check.
ryotak
Reputation: 46
6
chilaxan
ID-verifiedHacker that has successfully completed an ID verification check.
chilaxan
Reputation: 44
7
hashkitten
hashkitten
Reputation: 39
8
bugra
Clear-verified badgeHacker that has completed both ID-verification and a background check.
bugra
Reputation: 24
9
francisconeves97
francisconeves97
Reputation: 24
10
cjm00n
ID-verifiedHacker that has successfully completed an ID verification check.
cjm00n
Reputation: 24
11
z4n44
ID-verifiedHacker that has successfully completed an ID verification check.
z4n44
Reputation: 22
12
luhko
ID-verifiedHacker that has successfully completed an ID verification check.
luhko
Reputation: 22
Network Error: TypeError: Sorry, something went wrong. Please contact us at https://support.hackerone.com if this error persists