THREE vulnerabilities in the Paperclip AI platform have been exposed, allowing unauthenticated attackers to execute commands on servers. Two of the flaws are rated critical, including one with a CVSS score of 10.0, which enables attackers to register without email verification, giving them excessive permissions. Another flaw allows access to sensitive data without proper checks. A third vulnerability incorrectly treats local development requests as administrator actions, enabling attacks via DNS rebinding. All vulnerabilities were patched after disclosure.
Paperclip AI bugs allow attackers to run commands on servers
CyberSIXT Evidence Panel
Primary Source
oasis.security
Article by CyberSIXT
Timeline Coverage
Swipe to explore timeline
-
Paperclip AI flaw lets attackers run host commands via imports
thehackernews.com
-
Paperclip AI bugs allow attackers to run commands on servers
www.infosecurity-magazine.com