CVE Tools

Paperclip AI Flaws Let Attackers Run Host Commands via Malicious Agent Imports

The Hacker NewsBy The Hacker News

PoC publicPaperclip AI

Our summary

Three serious vulnerabilities in the open-source Paperclip AI control plane could allow attackers to run arbitrary commands on a host system or expose sensitive data. The most severe flaw, CVE-2026-41679 (CVSS 10.0), allows unauthenticated attackers to execute commands remotely without prior access. Another vulnerability, GHSA-x8hx-rhr2-9rf7 (CVSS 9.6), exploits default local configurations to launch attacks via DNS rebinding. A third issue involves improperly secured API routes that leak internal details. Paperclip has released a patch in version v2026.416.0, though some advisories still lack full version alignment. Users are urged to upgrade immediately.

Read at The Hacker News

The Hacker News publishes this story on its own site; we link to it rather than reprint it.

Worried this affects your company?

Discuss a security assessment of your internet-facing systems. Scope agreed before testing.

Check my exposure

We use analytics cookies to see which pages and articles actually help people. Decline and none of them run — the site works the same. What we store