logo

Paperclip AI Flaws Let Unauthenticated Attackers Run Commands

ID: 1afb81d2-de1e-5b6a-911d-5c419ff6e5a8

STIX ID: report--1afb81d2-de1e-5b6a-911d-5c419ff6e5a8

Feed Name: Infosecurity Magazine (News)

Threat Score
78/100

Date Published: 2026-08-05

Date Updated: 2026-08-05

...
...

Three critical vulnerabilities were found in the open-source Paperclip AI agent orchestration platform: a CVE-2026-41679 (CVSS 10.0) RCE path via self-registration and an import route that could launch attacker-specified commands on servers; GHSA-xfqj-r5qw-8g4j (CVSS 8.3) access-control omissions exposing heartbeat and agent metadata; and GHSA-x8hx-rhr2-9rf7 (CVSS 9.6) a DNS-rebinding issue that allowed attacker-controlled webpages to treat the local development instance as an admin and execute commands on developers' machines. The issues were patched in Paperclip 2026.416.0 and 0.3.1.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.