CVE Tools

@paperclipai/server

10 CVEs tracked. None of them is in CISA KEV.

This hub aggregates every CVE we track for @paperclipai/server, a product in the oss libraries space. Use it to gauge the current risk picture and drill into individual advisories.

@paperclipai/server CVEs per month

Oct 2024 to Sep 2026. Point at a month, or focus the strip and use the arrow keys.
@paperclipai/server CVEs per month
MonthCVEs
2024-100
2024-110
2024-120
2025-010
2025-020
2025-030
2025-040
2025-050
2025-060
2025-070
2025-080
2025-090
2025-100
2025-110
2025-120
2026-010
2026-020
2026-030
2026-0410
2026-050
2026-060
2026-070
2026-080
2026-090

Severity

How the 10 CVEs score on CVSS. Severity is not exploitation: KEV is counted above.

  • Critical150%
  • High150%

Latest CVEs

The 10 most recently published vulnerabilities affecting @paperclipai/server.

  1. CVE-2026-41679Paperclip Vulnerable to Unauthenticated Remote Code Execution via Import Authorization Bypass10.0
  2. CVE-2026-41208Paperclip: Privilege Escalation via Agent-Controlled workspaceStrategy.provisionCommand Leading to OS Command Execution8.8
  3. GHSA-3xx2-mqjm-hg9xPaperclip: Cross-tenant agent API key IDOR in `/agents/:id/keys` routes allows full victim-company compromise—
  4. GHSA-p7mm-r948-4q3qPaperclip: Approval decision attribution spoofing via client-controlled `decidedByUserId` in paperclip server—
  5. GHSA-47wq-cj9q-wpmpPaperclip: Cross-tenant agent API token minting via missing assertCompanyAccess on /api/agents/:id/keys—
  6. GHSA-vr7g-88fq-vhq3Paperclip: OS Command Injection via Execution Workspace cleanupCommand—
  7. GHSA-xfqj-r5qw-8g4jPaperclip: Unauthenticated Access to Multiple API Endpoints in Authenticated Mode—
  8. GHSA-w8hx-hqjv-vjcqPaperclip: Malicious skills able to exfiltrate and destroy all user data—
  9. GHSA-265w-rf2w-cjh4Paperclip: Privilege Escalation via Agent-Controlled workspaceStrategy.provisionCommand Leading to OS Command Execution—
  10. GHSA-68qg-g8mg-6pr7paperclip Vulnerable to Unauthenticated Remote Code Execution via Import Authorization Bypass—

Product grouping is registry-driven, with AI assist and human review. How it works

We use analytics cookies to see which pages and articles actually help people. Decline and none of them run — the site works the same. What we store