Two distinct isolation failures are now clearer, but neither should be overstated as a confirmed customer breach. In Vercel’s case, the strongest established fact is technical: a researcher reportedly escaped a Sandbox guest and obtained root on the host, defeating the principal microVM isolation boundary. Vercel’s maximum $50,000 bounty supports its severity assessment; it does not measure real-world incident impact. With no public CVE, affected versions, exploit chain, indicators, fleet scope, or evidence of production exploitation, we cannot infer cross-tenant access, credential theft, persistence, control-plane compromise, or customer-data exposure.
The defensible customer response is therefore assurance-driven rather than indicator-driven. Customers should ask Vercel to document whether production environments were affected, which regions and dates were in scope, when fleet-wide mitigation was completed, and whether hosts were patched, rebooted, or rebuilt. They also need answers about possible exposure of tenant memory, disks, metadata, and brokered credentials, together with the scope and results of retrospective hunting and any customer-specific findings. Until Vercel provides that detail, “confirmed critical escape” and “confirmed customer compromise” must remain separate statements.
The patched Manus issue exposes a related but different trust failure. Attacker-controlled instructions arrived indirectly through email, were obfuscated with JSFuck, and reportedly induced Node.js to decode them. Because decoding that representation executes JavaScript, code could run before the approval warning appeared; the proof of concept reportedly initiated a reverse-shell connection to researcher-controlled infrastructure. The content-filter bypass was only the entry mechanism. The deeper failure was allowing untrusted message content to become a privileged interpreter invocation without deterministic authorization occurring first. That establishes server-side execution within the agent-controlled environment, but not compromise of Manus’s wider platform or exploitation in the wild.
As we move to synthesis, the common lesson is to rank these cases by demonstrated boundary failure while keeping impact claims tied to evidence. Root on a host and server-side code execution are serious outcomes; bounty size, obfuscation, and proof-of-concept success do not by themselves establish customer harm or operational exploitation.