Today's cybersecurity headlines are brought to you by ThreatPerspective


Ethical Hacking News

Paperclip AI Vulnerabilities: A Comprehensive Analysis of the Flaws that Could Expose Sensitive Data


Paperclip AI has been found to contain two critical security flaws that could expose sensitive data and allow attackers to execute commands on a network server or a developer's computer. To mitigate these vulnerabilities, Paperclip AI has released a patch and developers should review their configuration to minimize the risk of exploitation.

  • Vulnerabilities CVE-2026-41679 and GHSA-x8hx-rhr2-9rf7 have been found in Paperclip AI, allowing attackers to execute commands on a network server or a developer's computer.
  • The more severe server-side path requires no pre-existing account interaction to access authenticated mode deployments.
  • A third flaw exposes sensitive data and control-plane details through API routes without proper access checks.
  • Paperclip AI has released a patch (version 2026.416.0) to mitigate the vulnerabilities, requiring instance-administrator access for imports targeting new companies and company access for existing ones.


  • Paperclip AI, an open-source control plane for teams of artificial intelligence (AI) agents, has been found to contain two critical security flaws that could allow attackers to execute commands on a network server or a developer's computer. These vulnerabilities, CVE-2026-41679 and GHSA-x8hx-rhr2-9rf7, have significant implications for the organization that uses Paperclip AI, as they could expose sensitive data and control-plane details.

    The more severe server-side path, tracked as CVE-2026-41679, requires no pre-existing account or victim interaction against network-accessible deployments using authenticated mode with the default registration configuration. This means that an attacker could register for a new instance of Paperclip AI without being invited or verified, sign in, and then execute commands on the server with operating-system privileges.

    The second path, tracked as GHSA-x8hx-rhr2-9rf7, requires a user to open an attacker-controlled page while Paperclip is running in its default local_trusted mode. This creates a vulnerability where an attacker could trick a developer into executing a malicious agent on their computer, which would then execute commands with the privileges of the server process.

    In addition to these vulnerabilities, a third flaw was discovered that exposes sensitive data and control-plane details through application programming interface (API) routes that did not enforce the expected access checks. This means that an attacker could retrieve sensitive information about Paperclip AI instances without needing valid credentials or access rights.

    The authors of this vulnerability, Oasis Security, have identified that Paperclip's built-in process adapter intentionally launches a configured command as a child process of the server. However, they also found that agent configuration can become executable behavior if not properly authorized. This created a situation where an unauthorized user or browser-originated requests could introduce and activate configuration that reached the launcher.

    To mitigate these vulnerabilities, Paperclip AI has released a patch, version 2026.416.0, which requires instance-administrator access for imports targeting a new company and company access for imports targeting an existing one. This ensures that only authorized users can execute commands on the server or a developer's computer.

    Rapid7 has also developed a public Metasploit module for CVE-2026-41679, which automates the six-request attack chain. The US Cybersecurity and Infrastructure Security Agency (CISA) has classified exploitation as proof-of-concept and marked it as automatable.

    It is essential that organizations using Paperclip AI update to version 2026.416.0 or later to prevent these vulnerabilities from being exploited. Furthermore, developers should review how registration and deployment exposure are configured to minimize the risk of exploitation.

    In conclusion, the vulnerabilities in Paperclip AI highlight the importance of proper security configuration and access controls when using open-source software. By understanding the risks associated with these vulnerabilities and taking steps to mitigate them, organizations can protect their sensitive data and prevent unauthorized access to their systems.

    Related Information:
  • https://www.ethicalhackingnews.com/articles/Paperclip-AI-Vulnerabilities-A-Comprehensive-Analysis-of-the-Flaws-that-Could-Expose-Sensitive-Data-ehn.shtml

  • https://thehackernews.com/2026/08/paperclip-ai-flaws-let-attackers-run.html

  • https://www.infosecurity-magazine.com/news/paperclip-ai-vulnerabilities-rce/

  • https://nvd.nist.gov/vuln/detail/CVE-2026-41679

  • https://www.cvedetails.com/cve/CVE-2026-41679/


  • Published: Wed Aug 5 12:12:24 2026 by llama3.2 3B Q4_K_M













    © Ethical Hacking News . All rights reserved.

    Privacy | Terms of Use | Contact Us