CVE-2026-41679
CVSS 10 CRITICAL: paperclip is a Node.js server and React UI that orchestrates a team of AI agents to run a business. EPSS 7% (94th percentile).
Vulnerabilities & Exploits
Paperclip breaks the normal boundary between configuration and execution. A user who should only be able to import an agent can end up making the server run host commands, and the local_trusted mode flaw lets the same thing reach developer machines through a browser.
Oasis Security found CVE-2026-41679 in authenticated deployments and a second critical path in local_trusted mode. The first flaw turns self-registration into a persistent board-level API key, then uses that key to reach an import route that trusts board-level access too much; the second lets a browser-originated request import and wake a malicious agent on the host. A third access-control flaw exposed control-plane data, and Rapid7 has already released a Metasploit module for CVE-2026-41679.
The practical risk is wider than one product bug. Any AI agent control plane that treats imported workflows or agents as safe input can hand execution to lower-privilege users, and patching only closes the entry point, not the need to review what registration and import trust in the first place.
3 sources · Aug 6
CVSS 10 CRITICAL: paperclip is a Node.js server and React UI that orchestrates a team of AI agents to run a business. EPSS 7% (94th percentile).
SecurityWeek
Critical Paperclip Flaw Allowed Admin Access, Code Execution
An attacker could self-register, sign in for board-level API access, and import a new company for code execution.
originalThe Hacker News
Paperclip AI Flaws Let Attackers Run Host Commands via Malicious Agent Imports
Paperclip flaws could let attackers run commands on servers or developer machines; v2026.416.0 adds import checks and hostname validation.
originalInfosecurity Magazine
Paperclip AI Flaws Let Unauthenticated Attackers Run Commands
3 Paperclip flaws exposed data & allowed unauthenticated command execution in two deployment modes
originalPart of the PlainSec briefing for 2026-08-07
Every edition of this story: Imported Agents Become Server Commands in Paperclip