logo

Critical Vulnerabilities in Paperclip AI Platform Enable Unauthenticated Command Execution

ID: 67b3f942-dbaa-57e1-9b72-ee1349598fde

STIX ID: report--67b3f942-dbaa-57e1-9b72-ee1349598fde

Feed Name: ThreatCluster

Threat Score
80/100

Date Published: 2026-08-05

Date Updated: 2026-08-05

...
...

Oasis Security reported three critical authorization vulnerabilities in the Paperclip AI agent platform that allow unauthenticated attackers to create accounts, obtain board-level API access, and execute arbitrary commands on servers and developer machines (notably CVE-2026-41679 with a CVSS score of 10.0). The flaws stem from design oversights in self-registration and company import flows; all issues have been patched in Paperclip releases 2026.416.0 and 0.3.1, and the report warns of systemic identity-boundary risks in AI agent control systems.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.