Close Menu
  • Home
  • News
  • Cyber Security
  • Internet of Things
  • Tips and Advice

Subscribe to Updates

Get the latest creative news from FooBar about art, design and business.

What's Hot

Paperclip AI Flaws Let Unauthenticated Attackers Run Commands

August 5, 2026

Prompt Injection Remains Biggest LLM Risk, Despite Limited Incidents

August 5, 2026

Critical Rails Flaw Could Let Unauthenticated Attackers Read Server Files via Image Uploads

August 5, 2026
Facebook X (Twitter) Instagram
Wednesday, August 5
Facebook X (Twitter) Instagram Pinterest Vimeo
Cyberwire Daily
  • Home
  • News
  • Cyber Security
  • Internet of Things
  • Tips and Advice
Cyberwire Daily
Home»Cyber Security»Paperclip AI Flaws Let Unauthenticated Attackers Run Commands
Cyber Security

Paperclip AI Flaws Let Unauthenticated Attackers Run Commands

Team-CWDBy Team-CWDAugust 5, 2026No Comments3 Mins Read
Share Facebook Twitter Pinterest LinkedIn Tumblr Reddit Telegram Email
Share
Facebook Twitter LinkedIn Pinterest Email


Three vulnerabilities in an open-source AI agent orchestration platform have exposed sensitive data and allowed unauthenticated command execution on servers and developers’ machines, with two rated critical and one carrying a maximum CVSS score of 10.0.

According to new research by Oasis Security published on August 4, the flaws affect Paperclip, a control plane its developers describe as a platform for operating zero-human companies. Oasis identified all three bugs during an assessment of its authenticated and local deployment modes.

The findings follow a run of similar disclosures, including a critical Flowise flaw and a Langflow bug exploited within 20 hours.

From Self-Registration to Code Execution

CVE-2026-41679 (CVSS 10.0) affected authenticated deployments. Paperclip allowed self-registration without email verification, and its CLI authorization flow let a new user approve their own credential challenge, turning that account into a persistent board-level API key with no separate approver.

That key reached the company import route. Paperclip restricted direct company creation to instance administrators, but the equivalent import path checked only for board-level access.

An attacker could use it to introduce a bundle containing an agent configured with the process adapter, a legitimate feature that launches a specified command as a child process. Waking that agent ran the attacker’s command with the server’s operating-system privileges.

A second finding, GHSA-xfqj-r5qw-8g4j (CVSS 8.3), covered several routes that omitted access checks entirely, exposing heartbeat data, agent documentation and health information.

Read more on RCE in AI agent platforms: Critical Flowise Flaw Gives Attackers Full Server Control

A Developer’s Browser as an Attack Path

A third flaw, GHSA-x8hx-rhr2-9rf7 (CVSS 9.6), reached the same execution sink from the opposite direction. Paperclip’s local development mode binds to loopback and treats every request as an implicit instance administrator, an assumption that holds for local clients but not browsers.

DNS rebinding let an attacker-controlled webpage cross that boundary. Once the attacker’s server became unreachable, the browser retried the hostname against loopback while still treating the connection as same-origin. Paperclip accepted the rebound requests as administrator actions, and the page imported and woke a malicious agent, executing commands on the developer’s machine.

Darren Guccione, CEO at Keeper Security, said the findings pointed to “a systemic failure in how AI agent control planes handle identity boundaries.” An attacker controlling an agent configuration does not merely reach data, he said, but can direct privileged action across every system that agent touches.

All three vulnerabilities were patched after disclosure. The two authenticated-mode findings were fixed in Paperclip 2026.416.0, which requires instance administrator privileges for new-company imports. The rebinding flaw was addressed in 0.3.1, enabling hostname validation in local mode.



Source

Share. Facebook Twitter Pinterest LinkedIn Tumblr Email
Previous ArticlePrompt Injection Remains Biggest LLM Risk, Despite Limited Incidents
Team-CWD
  • Website

Related Posts

Cyber Security

WhatsApp Scam Hijacks Accounts via Linked Devices Feature

August 4, 2026
Cyber Security

University of Arts London on Securing Creativity Against Cyber Threats

August 4, 2026
Cyber Security

Why the Browser is Becoming Security’s Front Line in the Age of AI

August 4, 2026
Add A Comment
Leave A Reply Cancel Reply

Latest News

North Korean Hackers Turn JSON Services into Covert Malware Delivery Channels

November 24, 202523 Views

macOS Stealer Campaign Uses “Cracked” App Lures to Bypass Apple Securi

September 7, 202517 Views

North Korean Hackers Target Crypto Firms with ClickFix and Zoom Lures

April 29, 202610 Views

Why SOC Burnout Can Be Avoided: Practical Steps

November 14, 20259 Views

BeyondTrust Patches Critical Auth Bypass Flaws in Remote Support and PRA

July 11, 20268 Views
Stay In Touch
  • Facebook
  • YouTube
  • TikTok
  • WhatsApp
  • Twitter
  • Instagram
Most Popular

North Korean Hackers Turn JSON Services into Covert Malware Delivery Channels

November 24, 202523 Views

macOS Stealer Campaign Uses “Cracked” App Lures to Bypass Apple Securi

September 7, 202517 Views

North Korean Hackers Target Crypto Firms with ClickFix and Zoom Lures

April 29, 202610 Views
Our Picks

Look out for phony verification pages spreading malware

September 14, 2025

Why children’s data is a long-term identity risk

June 3, 2026

What are brushing scams and how do I stay safe?

December 24, 2025

Subscribe to Updates

Get the latest news from cyberwiredaily.com

Facebook X (Twitter) Instagram Pinterest
  • Home
  • Contact
  • Privacy Policy
  • Terms of Use
  • California Consumer Privacy Act (CCPA)
© 2026 All rights reserved.

Type above and press Enter to search. Press Esc to cancel.