Threat Advisory

Paperclip Flaw Enables Remote Code Execution and Data Exposure

Threat: Vulnerability
Targeted Region: Global
Targeted Sector: Technology & IT
Criticality: High
[subscribe_to_unlock_form]

EXECUTIVE SUMMARY:

A CVE-2026-41679 with a CVSS score of 9.8 is a vulnerability affecting Paperclip versions, while creating a new company directly required instance administrator privileges, importing a company enforced only board-level permissions in the open-source AI agent platform Paperclip that could be chained into remote code execution (RCE), data exposure, and developer-machine compromise. The flaw type affects authenticated deployments using Paperclip’s default registration settings, allowing an attacker to obtain persistent board-level API access without requiring separate administrative approval. This permission was sufficient to exploit another authorization mismatch issue in the platform’s company import workflow. An attacker could upload a malicious “.paperclip.yaml” file specifying a process-based agent and then trigger that agent to execute arbitrary operating system commands under the Paperclip server's privileges. The bugs exploited the same underlying assumption, highlighting architectural flaws in how AI agent control planes handle identity boundaries. This issue is now patched with fixes shipped in versions 2026.416.0 and 0.3.1. Affected versions include those prior to version 2026.416.0, where while creating a new company directly required instance administrator privileges, importing a company enforced only board-level permissions.

RECOMMENDATION:

We recommend you to update Paperclip to version 2026.416.0 or 0.3.1.[/subscribe_to_unlock_form]

EXECUTIVE SUMMARY:

A CVE-2026-41679 with a CVSS score of 9.8 is a vulnerability affecting Paperclip versions, while creating a new company directly required instance administrator privileges, importing a company enforced only board-level permissions in the open-source AI agent platform Paperclip that could be chained into remote code execution (RCE), data exposure, and developer-machine compromise. The flaw type affects authenticated deployments using Paperclip’s default registration settings, allowing an attacker to obtain persistent board-level API access without requiring separate administrative approval. This permission was sufficient to exploit another authorization mismatch issue in the platform’s company import workflow. An attacker could upload a malicious “.paperclip.yaml” file specifying a process-based agent and then trigger that agent to execute arbitrary operating system commands under the Paperclip server's privileges. The bugs exploited the same underlying assumption, highlighting architectural flaws in how AI agent control planes handle identity boundaries. This issue is now patched with fixes shipped in versions 2026.416.0 and 0.3.1. Affected versions include those prior to version 2026.416.0, where while creating a new company directly required instance administrator privileges, importing a company enforced only board-level permissions.

RECOMMENDATION:

We recommend you to update Paperclip to version 2026.416.0 or 0.3.1.[emaillocker id="1283"]

REFERENCES:

The following reports contain further technical details:

[/emaillocker]
crossmenu