Malte Ubl
@cramforce
Followers
44K
Following
50K
Media
3K
Statuses
58K
Self-driving infrastructure @Vercel CTO. Immigrant πΊπΈ/π©πͺ/acc
San Francisco
Joined July 2008
Futures Traders: Now you can get 30% off for life, never pay an activation fee, and get 100% initial test refunds with your first withdrawal! Use code NOFEE100 to claim this limited time offer.
0
12
74
7
6
111
This event starts at 9:15pm so the 996 folks can make
holiday parties are boring so we're hosting a demo night instead! join us at the brand new @vercel office next week for our backends demo night with some of the top founders and builders in SF link to rsvp below. see you there β¨
1
0
29
holiday parties are boring so we're hosting a demo night instead! join us at the brand new @vercel office next week for our backends demo night with some of the top founders and builders in SF link to rsvp below. see you there β¨
12
6
120
In localdev, when something fundamental is missing like an API key, there is often a challenge that long stack traces can obfuscate how to fix what is almost like a 1-time onboarding error. What should the library do?
1
0
5
Introducing shadcn/create β Build your own shadcn/ui Customize Everything. Pick your component library, icons, base color, theme, fonts and build something that doesnβt look like everything else. Now available for Next.js, Vite, TanStack Start and v0.
465
1K
9K
Mode slug cursor-thinking-4x-ultra-brute-force-yolo
4
0
33
One of those moments where AI shows you the future
1
1
22
We keep hearing that somehow, a single account number is more secure than a username+password combo. We got tired of asking how this makes sense and instead just implemented it into our service, but more secure since it's a hash instead of a number! π
11
8
94
Introducing AI SDK DevTools Get full visibility into your LLM calls and agents with our new experimental package.
35
64
718
i'm looking for someone truly obsessed with web performance to join the Next.js team no need for prior framework experience, just strong React skills and real product performance wins :) if you love squeezing every millisecond out of the web, please reach out π
87
31
522
We automatically fixed and re-deployed over 800K projects generated by @v0 to protect from React2Shell. It took about 8K machine hours of deploy time
v0 has now automatically updated every React2Shell-vulnerable project deployed with v0, covering more than 800,000 affected deployments.
8
2
253
Clerk is now available as a Workflow Builder plugin Try it out with this "Role Upgrade Automation" example: https://t.co/eR6k8wdwtm
4
3
91
The @vercel Agent can now apply security patches and open PRs. Unlike classical solutions, AI agents can figure out complex monorepos, work across package managers, bump peer dependencies, etc. Amazing work by @allenzhou101 @witsdev @tomdale.
Vercel Agent can now automatically detect React2Shell-vulnerable projects and open PRs that patch your code to safe versions. Whether automated or manual, patch your projects today. https://t.co/dPlrJeY0as
28
21
248
We want to thank the hackerone community for an incredible collaboration over the weekend. They discovered a total of 15 unique issues, leading to an expected payout of $750K. Our eng team has hardened the WAF as issues were discovered, and the last "flag capture" was 20 hours
vercel.com
CVE-2025-55182 is a critical vulnerability in React, Next.js, and other frameworks that requires immediate action
We introduced a dedicated HackerOne program for Vercel WAF bypasses for CVE-2025-55182 / react2shell Critical bypass: $50K https://t.co/90NnL06Vnx
20
47
536
The latest on React2Shell: β’ Upgrade to a patched version immediately β’ Use πππ‘ πππ‘-ππππππΈπππππ-πππ‘π to start β’ Rotate secrets Updates and guidance will be published in the React2Shell Bulletin β
vercel.com
CVE-2025-55182 is a critical vulnerability in React, Next.js, and other frameworks that requires immediate action
5
26
207
So, CVE-2025-55182 is trending for good reason. If you have external webapps in your company, your leaders need to force techies to come in on the weekend and fix it. IT/security departments need to have an "emergency budget" when they force workers to stay late or come in on
16
36
357