CRITICAL ISSUE: Unauthorized User Hijacking All Deployments

I’m experiencing a critical security vulnerability where an unauthorized GitHub user “renoschubert” is appearing as the author on ALL my deployments, including completely fresh projects.

What’s Happening:

  • Every deployment shows “renoschubert” as the deployer

  • This affects both manual and automatic deployments

  • Issue persists even on brand new projects with no previous deployments

  • Happens across multiple repositories and project names

What I’ve Tried:

:white_check_mark: Disconnected/reconnected GitHub integration

:white_check_mark: Deleted suspicious deployments

:white_check_mark: Created completely new projects

:white_check_mark: Verified no collaborators on GitHub repos

:white_check_mark: Checked all account permissions

Security Impact:

This represents a system-level security breach where:

  • Unauthorized users can access deployment infrastructure

  • Deployment logs are being falsified

  • Multiple projects are affected simultaneously

  • Fresh projects are compromised immediately

Urgency:

This is a CRITICAL security issue that affects the entire Vercel platform. I cannot safely deploy any projects until this is resolved.

Request:

Please escalate this to Vercel security team immediately. This appears to be a platform-wide vulnerability, not a user-specific issue.

I’m having the same issue. Any fix?

In Cursor, I had duplicate github logins, and one of them had the email address “your.email@example.com” or similar. Error on my part (vibe-coding noob) to have the second login. Deleted that and now my deployments are flowing smoothly from Cursor > Github > Vercel.

1 Like

This topic was automatically closed 90 days after the last reply. New replies are no longer allowed.