vulnerability
Critical Paperclip Flaw Allowed Admin Access, Code Execution
Critical
Summary
A critical vulnerability (CVE-2026-41679) in Paperclip, an AI management platform, allowed remote attackers to gain administrative access and execute code on the server, potentially exposing sensitive data and internal services. The flaw stemmed from a missing authorization check during company import, enabling attackers to bypass security controls and deploy malicious agents. The vulnerability has been patched, and two additional bugs related to API routes and DNS rebinding have also been addressed.
Summary written automatically in our own words from the original article, which belongs to its publisher and remains the reference. It may contain errors. Sources & data