LIVE · cybersecurity feed
Live wire
breach

Paperclip AI Flaws Let Unauthenticated Attackers Run Commands

3 Paperclip flaws exposed data & allowed unauthenticated command execution in two deployment modes

zeroday.news · 2h ago

Three critical vulnerabilities have been identified in Paperclip, an open-source AI agent orchestration platform, potentially allowing unauthenticated command execution on servers and developer machines, as well as exposing sensitive data. The flaws were discovered by Oasis Security during an assessment of Paperclip's authenticated and local deployment modes.

One vulnerability, tracked as CVE-2026-41679, received a CVSS score of 10.0. This flaw affected authenticated deployments, stemming from Paperclip's self-registration process, which lacked email verification. An attacker could exploit the command-line interface (CLI) authorization flow to approve their own credential challenge, thereby obtaining a persistent board-level API key. This key could then be used with the company import route. Although direct company creation was restricted to instance administrators, the import path only checked for board-level access. Attackers could leverage this to introduce a bundle containing an agent configured with the process adapter, a legitimate feature designed to launch specified commands as child processes. Activating this malicious agent would then execute the attacker's command with the server's operating system privileges.

A second issue, identified as GHSA-xfqj-r5qw-8g4j (CVSS 8.3), involved several routes that lacked proper access checks. This oversight exposed sensitive information such as heartbeat data, agent documentation, and health status.

The third vulnerability, GHSA-x8hx-rhr2-9rf7 (CVSS 9.6), allowed for remote code execution in Paperclip's local development mode. In this mode, Paperclip binds to the loopback interface and implicitly treats all requests as originating from an instance administrator. While this assumption holds for local clients, it does not account for browsers. An attacker could exploit DNS rebinding to bypass this boundary. An attacker-controlled webpage could cause a browser to retry a hostname against the loopback interface once the attacker's server became unreachable, while still maintaining a same-origin connection. Paperclip would then accept these rebound requests as administrator actions, allowing the malicious webpage to import and activate an agent, executing commands on the developer's machine.

Paperclip's developers describe the platform as a control plane for operating "zero-human companies," which underscores the potential impact of these vulnerabilities on automated systems.

All three vulnerabilities have been patched following their disclosure. The two flaws affecting authenticated deployments were addressed in Paperclip version 2026.416.0, which now mandates instance administrator privileges for new-company imports. The DNS rebinding vulnerability in local development mode was fixed in version 0.3.1, which introduces hostname validation.

breachvulnerabilityaicloud
ShareXLinkedInWhatsAppFacebook

More News

view all →
breach

311,000 Impacted by Brown Health Medical Group-MA Data Breach

Hackers stole personal information, medical records, and financial information from the organization’s server. The post 311,000 Impacted by Brown Health Medical Group-MA Data Breach appeared first on SecurityWeek.

ddos

“I’m Allowed”: Hackers Use Simple Claims to Bypass AI Guardrails

Cisco Talos found hackers using simple authorization claims to bypass AI guardrails, build DDoS attack tools, steal credentials and access live camera services.

ai

Stellar Cyber’s Auto-Triage AI matches human analysts 99.7% of the time

Stellar Cyber, the full-cycle AI-native security operations platform company, today released results from an independent study of 124 days of customer trials of its Agentic Auto Triage capability. The independent study based on customer trials evaluated 138,475 real security alerts and reached the same verdict as human analysts 99.7% of the time. The findings, drawn from customer-submitted end-of-

ai

AI agent deception moves from theory to reality in UK cyber tests

“During a routine cyber evaluation, AI agents took sustained, unsanctioned action directed at real people and organisations,” UK’s AI Security Institute (AISI) disclosed on Tuesday. The agents’ actions included an attempted supply-chain attack that saw them create malicious pull requests and try to socially engineer an open-source maintainer into approving the malicious code (they refused). The ag

security

Uppsala Security Becomes First Blockchain Intelligence Company to Join Cyber Threat Alliance

SIngapore, Singapore, 5th August 2026, CyberNewswire

CVE-2026-68742

Indian Cybersecurity Firm Uses Homegrown AI to Discover Three Security Flaws in Enterprise Linux

Bengaluru-based BreachX says its internally built Typhon AI model uncovered three previously unknown vulnerabilities in SSSD, the identity component that handles authentication across enterprise Linux. Red Hat has assigned CVE-2026-68742, CVE-2026-68743 and CVE-2026-68744 and credited the firm’s Zero Day Research Labs with the coordinated disclosure.