Paperclip AI Flaws Let Unauthenticated Attackers Run Commands
ID: 1afb81d2-de1e-5b6a-911d-5c419ff6e5a8
STIX ID: report--1afb81d2-de1e-5b6a-911d-5c419ff6e5a8
Feed Name: Infosecurity Magazine (News)
Three critical vulnerabilities were found in the open-source Paperclip AI agent orchestration platform: a CVE-2026-41679 (CVSS 10.0) RCE path via self-registration and an import route that could launch attacker-specified commands on servers; GHSA-xfqj-r5qw-8g4j (CVSS 8.3) access-control omissions exposing heartbeat and agent metadata; and GHSA-x8hx-rhr2-9rf7 (CVSS 9.6) a DNS-rebinding issue that allowed attacker-controlled webpages to treat the local development instance as an admin and execute commands on developers' machines. The issues were patched in Paperclip 2026.416.0 and 0.3.1.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
