Paperclip AI Flaws: Critical RCE via Malicious Agent Imports
Summary
New security flaws in Paperclip could allow attackers to run commands on network servers or developer computers. Paperclip is an open-source control plane for AI agent teams. Attackers can exploit these flaws by importing and starting a malicious agent. One severe server-side path, tracked as CVE-2026-41679, has a CVSS score of 10.0. This path requires no existing account or user interaction against vulnerable network deployments. A second path, GHSA-x8hx-rhr2-9rf7, rated 9.6, requires a user to open an attacker-controlled page while Paperclip runs in its default mode. Another flaw could expose sensitive data through API routes without proper access checks. Paperclip version 2026.416.0 contains fixes for some of these issues. Operators should update to this version or later and review their registration and deployment settings. This is important because these vulnerabilities could give unauthorized users control over your systems.
This is an AI-generated audio summary. Always check the original source for complete reporting.