Paperclip AI Flaws Let Attackers Run Host Commands via Malicious Agent Imports
Two critical vulnerabilities in Paperclip, an AI agent control plane, allow attackers to execute commands on a server or a developer's computer. The first vulnerability (CVE-2026-41679) requires no prior account or interaction, enabling attackers to import malicious agents and run commands with server privileges. The second vulnerability (GHSA-xfqj-r5qw-8g4j) stems from a DNS rebinding attack in local mode, allowing attackers to bypass authentication and install agents. Both vulnerabilities have been addressed in version 2026.416.0, which requires an upgrade. Rapid7 has released a Metasploit module to automate the attack chain, and CISA has classified the flaw as automatable. The vulnerabilities stem from a lack of proper authorization checks and trust in network locations, potentially exposing sensitive data and internal services.
Summary written automatically in our own words from the original article, which belongs to its publisher and remains the reference. It may contain errors. Sources & data
