Paperclip Unclipped: The 9.8 CVSS Flaw Handing Your AI Agents to the Public
ID: 924fa745-8aed-5bcb-8690-ff6285452fc4
STIX ID: report--924fa745-8aed-5bcb-8690-ff6285452fc4
Feed Name: securityonline.info
**Executive summary:** Paperclip, a Node.js/React orchestration platform for autonomous agents, contains three critical vulnerabilities — a shell command injection in workspace cleanup (RCE), a cross-tenant API key minting/impersonation allowing full tenant compromise, and a cross-tenant agent listing information leak — affecting versions up to 2026.410.0-canary.1; the report provides PoCs and recommends immediate upgrade to v2026.416.0+, input sanitization, and replacing shell spawn calls with execFile().
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
