CVE-2026-41679
CVSS 10 CRITICAL: paperclip is a Node.js server and React UI that orchestrates a team of AI agents to run a business. EPSS 19% (97th percentile).
Vulnerabilities & Exploits · Web App Attack
A public Metasploit module makes Paperclip AI immediately testable, and that changes the tempo more than the CVE itself. Once the exploit is in a framework, the jump from proof to active use gets much shorter, and the same release adds persistence and post-exploitation paths that extend the blast radius past the first web shell.
Rapid7’s release adds an unauthenticated exploit for CVE-2026-41679, which affects network-accessible Paperclip instances running in authenticated mode with default configuration. It also adds an NTLM relay-to-self local privilege escalation, a VS Code extension persistence module, and MCP server integration that lets AI tools assist inside msfconsole.
The practical risk is not just initial access. It is the speed with which an operator can move from exposed app to durable foothold and then into higher privileges using the same framework session.
1 source · Jun 19
CVSS 10 CRITICAL: paperclip is a Node.js server and React UI that orchestrates a team of AI agents to run a business. EPSS 19% (97th percentile).
Rapid7
Metasploit Wrap-Up 19/06/2026
This week's release adds a full unauthenticated RCE chain for Paperclip AI, an NTLM relay-to-self local priv esc module, a VS Code extension persistence technique, MCP server integration for AI-assisted msfconsole operation, and more.
originalPart of the PlainSec briefing for 2026-06-19
Every edition of this story: Metasploit Turns Paperclip AI Into a Live Target