Critical Vulnerabilities in Paperclip AI Platform Enable Unauthenticated Command Execution

Critical Vulnerabilities in Paperclip AI Platform Enable Unauthenticated Command Execution

First seen 5 Aug 2026, 15:41 UTC CsoonlineInfosecurity-Magazinewww.oasis.security 84% similarity 78.0

Article Content

Browse articles
ThreatCluster

Oasis Security identified three critical vulnerabilities in the Paperclip AI agent platform, allowing unauthenticated attackers to execute arbitrary commands on servers and developer machines. The flaws stem from a design oversight in authorization checks, particularly in the self-registration process and company import workflows. An attacker could create an account without email verification, gain board-level API access, and exploit the system to run malicious commands. The vulnerabilities include CVE-2026-41679, which has a CVSS score of 10.0, and other issues that expose sensitive API endpoints. All vulnerabilities were patched in versions 2026.416.0 and 0.3.1. The findings highlight systemic failures in how AI agent control systems manage identity boundaries, posing risks beyond just Paperclip.

Key Points: • Three critical vulnerabilities in Paperclip allow unauthenticated command execution. • CVE-2026-41679 has a maximum CVSS score of 10.0, indicating severe risk. • All vulnerabilities have been patched in the latest releases of Paperclip.

ThreatCluster AI How this analysis works

Timeline

2026-04-23
CVE-2026-41679 published
A critical vulnerability in Paperclip allows unauthenticated users to gain board-level API access and execute commands.
Infosecurity-Magazine
2026-08-05
Vulnerabilities disclosed by Oasis Security
Oasis Security published details of three critical vulnerabilities in Paperclip affecting various deployment modes.
Csoonline
2026-08-05
Patches released for Paperclip vulnerabilities
Paperclip released version 2026.416.0 and 0.3.1 to address the identified vulnerabilities.
Oasis Security

Community

Browse all →