logo

Paperclip Unclipped: The 9.8 CVSS Flaw Handing Your AI Agents to the Public

ID: 924fa745-8aed-5bcb-8690-ff6285452fc4

STIX ID: report--924fa745-8aed-5bcb-8690-ff6285452fc4

Feed Name: securityonline.info

Threat Score
92/100

Date Published: 2026-04-20

Date Updated: 2026-04-23

Author: Ddos

...
...

**Executive summary:** Paperclip, a Node.js/React orchestration platform for autonomous agents, contains three critical vulnerabilities — a shell command injection in workspace cleanup (RCE), a cross-tenant API key minting/impersonation allowing full tenant compromise, and a cross-tenant agent listing information leak — affecting versions up to 2026.410.0-canary.1; the report provides PoCs and recommends immediate upgrade to v2026.416.0+, input sanitization, and replacing shell spawn calls with execFile().

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.