@paperclipai/server
10 CVEs tracked. None of them is in CISA KEV.
This hub aggregates every CVE we track for @paperclipai/server, a product in the oss libraries space. Use it to gauge the current risk picture and drill into individual advisories.
@paperclipai/server CVEs per month
| Month | CVEs |
|---|---|
| 2024-10 | 0 |
| 2024-11 | 0 |
| 2024-12 | 0 |
| 2025-01 | 0 |
| 2025-02 | 0 |
| 2025-03 | 0 |
| 2025-04 | 0 |
| 2025-05 | 0 |
| 2025-06 | 0 |
| 2025-07 | 0 |
| 2025-08 | 0 |
| 2025-09 | 0 |
| 2025-10 | 0 |
| 2025-11 | 0 |
| 2025-12 | 0 |
| 2026-01 | 0 |
| 2026-02 | 0 |
| 2026-03 | 0 |
| 2026-04 | 10 |
| 2026-05 | 0 |
| 2026-06 | 0 |
| 2026-07 | 0 |
| 2026-08 | 0 |
| 2026-09 | 0 |
Severity
How the 10 CVEs score on CVSS. Severity is not exploitation: KEV is counted above.
- Critical1
- High1
Latest CVEs
The 10 most recently published vulnerabilities affecting @paperclipai/server.
- CVE-2026-41679Paperclip Vulnerable to Unauthenticated Remote Code Execution via Import Authorization Bypass10.0
- CVE-2026-41208Paperclip: Privilege Escalation via Agent-Controlled workspaceStrategy.provisionCommand Leading to OS Command Execution8.8
- GHSA-3xx2-mqjm-hg9xPaperclip: Cross-tenant agent API key IDOR in `/agents/:id/keys` routes allows full victim-company compromise—
- GHSA-p7mm-r948-4q3qPaperclip: Approval decision attribution spoofing via client-controlled `decidedByUserId` in paperclip server—
- GHSA-47wq-cj9q-wpmpPaperclip: Cross-tenant agent API token minting via missing assertCompanyAccess on /api/agents/:id/keys—
- GHSA-vr7g-88fq-vhq3Paperclip: OS Command Injection via Execution Workspace cleanupCommand—
- GHSA-xfqj-r5qw-8g4jPaperclip: Unauthenticated Access to Multiple API Endpoints in Authenticated Mode—
- GHSA-w8hx-hqjv-vjcqPaperclip: Malicious skills able to exfiltrate and destroy all user data—
- GHSA-265w-rf2w-cjh4Paperclip: Privilege Escalation via Agent-Controlled workspaceStrategy.provisionCommand Leading to OS Command Execution—
- GHSA-68qg-g8mg-6pr7paperclip Vulnerable to Unauthenticated Remote Code Execution via Import Authorization Bypass—
Product grouping is registry-driven, with AI assist and human review. How it works