Paperclip AI Flaws Let Attackers Run Host Commands via Malicious Agent Imports
Two critical vulnerabilities in Paperclip, an open-source control plane for AI agents, could allow attackers to execute arbitrary commands on a server…
Two critical vulnerabilities in Paperclip, an open-source control plane for AI agents, could allow attackers to execute arbitrary commands on a server…
A critical vulnerability in Paperclip's authenticated mode with default registration allows unauthenticated attackers to self-approve credentials and import a malicious agent, leading…
NVD carries CISA-ADP enrichment for CVE-2026-41679 and retains older affected-version metadata, causing version label confusion.
Rapid7 released a Metasploit module automating the attack chain for CVE-2026-41679, enabling penetration testers to exploit the Paperclip vulnerability.
Rapid7 developed and released a Metasploit module for CVE-2026-41679, aiding security testing of Paperclip deployments.