Paperclip AI Flaws Let Attackers Run Host Commands via Malicious Agent Imports
Two critical vulnerabilities in Paperclip, an open-source control plane for AI agents, could allow attackers to execute arbitrary commands on a server…
Two critical vulnerabilities in Paperclip, an open-source control plane for AI agents, could allow attackers to execute arbitrary commands on a server…
A critical vulnerability in Paperclip's authenticated mode with default registration allows unauthenticated attackers to self-approve credentials and import a malicious agent, leading…
A high-severity flaw in Paperclip's local_trusted mode allows DNS rebinding attacks to execute commands on the developer's machine with CVSS 9.6. Fixed…
Multiple API routes in Paperclip lacked proper access checks, exposing sensitive data and control-plane details. Fixed in v2026.416.0 with added authentication and…
Paperclip is an open-source control plane for managing teams of AI agents. It suffered critical vulnerabilities allowing remote code execution via malicious…
Oasis Security analyzed and reported the Paperclip vulnerabilities, providing a 17-page technical report and recommending upgrades to v2026.416.0.