CVE-2026-41679
10.0
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
Exploitability: 3.9 / Impact: 6.0
Source: security-advisories@github.com (Secondary)
Description
Paperclip is a Node.js server and React UI that orchestrates a team of AI agents to run a business. Prior to version 2026.416.0, an unauthenticated attacker can achieve full remote code execution on any network-accessible Paperclip instance running in `authenticated` mode with default configuration. No user interaction, no credentials, just the target's address. The chain consists of six API calls. The attack is fully automated, requires no user interaction, and works against the default deployment configuration. Version 2026.416.0 patches the issue.
Affected (2)
Products: Paperclip: Paperclipai, Paperclipai/server
Configuration A
| Vulnerable Software | Affected Versions |
|---|---|
| Before 2026.416.0 | |
| Before 2026.416.0 |
Related CWEs
CWE-1188
Initialization of a Resource with an Insecure Default
The product initializes or sets a resource with a default that is intended to be changed by the administrator, but the default is not secure.
CWE-287
Improper Authentication
When an actor claims to have a given identity, the product does not prove or insufficiently proves that the claim is correct.
CWE-862
Missing Authorization
The product does not perform an authorization check when an actor attempts to access a resource or perform an action.
References (2)
Source: security-advisories@github.com
ExploitMitigationThird Party Advisory
Source: 134c704f-9b21-4f2e-91b3-4a467353bcc0
ExploitMitigationThird Party Advisory
Timeline
No history available yet.