Vercel breach traced to AI tool after employee grants unrestricted Google Workspace access
Vercel, the cloud platform behind Next.js, disclosed a security breach originating from Context.ai, a third-party AI tool. A Vercel employee granted the AI tool unrestricted OAuth permissions to their corporate Google Workspace account. When Context.ai was compromised through infostealer malware, attackers inherited those permissions and accessed Vercel's internal systems, exposing non-sensitive environment variables for a limited subset of customers.