3 Paperclip flaws exposed data & allowed unauthenticated command execution in two deployment modes

Three critical vulnerabilities have been identified in Paperclip, an open-source AI agent orchestration platform, potentially allowing unauthenticated command execution on servers and developer machines, as well as exposing sensitive data. The flaws were discovered by Oasis Security during an assessment of Paperclip's authenticated and local deployment modes.
One vulnerability, tracked as CVE-2026-41679, received a CVSS score of 10.0. This flaw affected authenticated deployments, stemming from Paperclip's self-registration process, which lacked email verification. An attacker could exploit the command-line interface (CLI) authorization flow to approve their own credential challenge, thereby obtaining a persistent board-level API key. This key could then be used with the company import route. Although direct company creation was restricted to instance administrators, the import path only checked for board-level access. Attackers could leverage this to introduce a bundle containing an agent configured with the process adapter, a legitimate feature designed to launch specified commands as child processes. Activating this malicious agent would then execute the attacker's command with the server's operating system privileges.
A second issue, identified as GHSA-xfqj-r5qw-8g4j (CVSS 8.3), involved several routes that lacked proper access checks. This oversight exposed sensitive information such as heartbeat data, agent documentation, and health status.
The third vulnerability, GHSA-x8hx-rhr2-9rf7 (CVSS 9.6), allowed for remote code execution in Paperclip's local development mode. In this mode, Paperclip binds to the loopback interface and implicitly treats all requests as originating from an instance administrator. While this assumption holds for local clients, it does not account for browsers. An attacker could exploit DNS rebinding to bypass this boundary. An attacker-controlled webpage could cause a browser to retry a hostname against the loopback interface once the attacker's server became unreachable, while still maintaining a same-origin connection. Paperclip would then accept these rebound requests as administrator actions, allowing the malicious webpage to import and activate an agent, executing commands on the developer's machine.
Paperclip's developers describe the platform as a control plane for operating "zero-human companies," which underscores the potential impact of these vulnerabilities on automated systems.
All three vulnerabilities have been patched following their disclosure. The two flaws affecting authenticated deployments were addressed in Paperclip version 2026.416.0, which now mandates instance administrator privileges for new-company imports. The DNS rebinding vulnerability in local development mode was fixed in version 0.3.1, which introduces hostname validation.

Hardware wallet manufacturer Trezor on Friday disclosed that another 67,000 customers from the U.S. have been impacted in a breach at its shipping provider ShipMonk. The exposed information includes customer names, email addresses, phone numbers, shipping addresses, and order numbers between November 2019 and August 2021. The breach does not affect the security of the company's hardware wallets

OpenAI admits it did not disclose an incident where autonomous AI agents hijacked a German wiki, created 18,000 posts, shared answers, and bypassed restrictions, saying it treated the activity as model "misalignment" rather than a security breach. [...]

A massive cybercriminal operation is leveraging thousands of compromised small-business websites to deliver ClickFix payloads stored in smart contracts on the BNB Smart Chain (BSC). [...]

A critical arbitrary file upload vulnerability in the Elementor Pro WordPress plugin, tracked as CVE-2026-32475, is being actively exploited to compromise websites. The flaw exists in the plugin's form submission handling function, allowing attackers to upload malicious files.

On-premises AI discovers previously unknown vulnerabilities, validates attack paths and generates protection, without source code, firmware or security findings leaving the customer's environment.

Plus: Tens of millions of US and Canadian drivers’ licenses go up for sale on the dark web, the US military finally tries to tackle the risk online ad data poses to troops, and more.