logo

Critical Paperclip AI Flaws Enable Unauthenticated RCE and Agent Takeover

ID: b25b88b0-c30d-55ad-9344-87cffcb3b263

STIX ID: report--b25b88b0-c30d-55ad-9344-87cffcb3b263

Feed Name: Cyber Press

Threat Score
90/100

Date Published: 2026-08-06

Date Updated: 2026-08-06

Author: Tamilselvan

...
...

Oasis disclosed three critical/high vulnerabilities in the Paperclip AI control plane—most notably CVE-2026-41679 (CVSS 10.0)—that allow an unauthenticated attacker to self-register, mint a board-level API token, abuse an import route to create a process-based agent, and achieve remote code execution on the Paperclip server; additional issues enable information leakage and a DNS-rebinding attack against Paperclip's default local_trusted mode that grants admin privileges to loopback requests. Operators are advised to upgrade to patched versions (2026.416.0 and post-0.3.1 for local mode), disable open registration where appropriate, and treat agent configurations as executable code.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.