Critical Vulnerabilities in Paperclip AI Platform Enable Unauthenticated Command Execution
ID: 67b3f942-dbaa-57e1-9b72-ee1349598fde
STIX ID: report--67b3f942-dbaa-57e1-9b72-ee1349598fde
Feed Name: ThreatCluster
Oasis Security reported three critical authorization vulnerabilities in the Paperclip AI agent platform that allow unauthenticated attackers to create accounts, obtain board-level API access, and execute arbitrary commands on servers and developer machines (notably CVE-2026-41679 with a CVSS score of 10.0). The flaws stem from design oversights in self-registration and company import flows; all issues have been patched in Paperclip releases 2026.416.0 and 0.3.1, and the report warns of systemic identity-boundary risks in AI agent control systems.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
