Critical Paperclip Flaw Allowed Admin Access, Code Execution
AdvisoryPaperclipOur summary
Oasis Security has disclosed a critical authorization bypass in the Paperclip AI management platform, tracked as CVE-2026-41679 with a perfect CVSS score of 10. The vulnerability enabled remote attackers to register accounts without email verification and self-approve CLI challenges to gain board-level API access. By exploiting a gap in the company import process, attackers could upload crafted YAML files that executed arbitrary commands with the privileges of the Paperclip server process. The vendor has released a fix that applies strict authorization checks to import flows and tightens company scoping, also addressing related issues involving data disclosure and DNS rebinding.
SecurityWeek publishes this story on its own site; we link to it rather than reprint it.
Worried this affects your company?
Discuss a security assessment of your internet-facing systems. Scope agreed before testing.