www.securityweek.com 8/6/2026, 11:21:21 AM · external

Critical Paperclip AI flaw allows attackers full server control

Critical Paperclip AI flaw allows attackers full server control
CyberSIXT Evidence Panel
Primary Source pages.oasis.security
CISA KEV Not in KEV
Patch Patch Status Unknown

OASIS Security reported a critical security flaw in the Paperclip AI management platform, tracked as CVE-2026-41679, with a CVSS score of 10. This vulnerability allowed remote attackers to bypass authorization, self-register, and obtain arbitrary code execution with the server’s permissions. Attackers could exploit a missing authorization check to sign into Paperclip, create a CLI challenge, and deploy agents.

The flaw affected instances with default authenticated-mode configurations, enabling unauthorized account creation and exploitation of board API access. Paperclip has since patched this vulnerability by improving access controls, but other issues were also addressed, including sensitive data exposure through API routes and a DNS rebinding weakness. The report highlights the risks associated with AI agent workflows and stresses the importance of stricter authorization checks.

View Primary Source Via www.securityweek.com

Article by CyberSIXT