Two vulnerabilities exist within Paperclip, an open-source control plane for AI teams, allowing attackers to execute commands on network servers or developers' machines This article explores vulnerabilities exist paperclip. . The third flaw exposes sensitive data through unenforced access checks via application programming interface (API) routes in default local_trusted mode.
The more severe server-side path, tracked as CVE-2026-41679 (CVSS score: 10.0), necessitates no pre-existing account or user interaction on network-accessible deployments using authenticated mode with the default registration configuration. Oasis Security's evaluation, supported by a comprehensive 17-page technical document, ties together the results using a single product characteristic: agent configuration transforms into executable behavior. This absence doesn't preclude its potential for exploitation.
The proof of concept was successfully verified on macOS with Firefox, but it's noted that this result may vary across different browsers and operating systems due to varying implementation details. Other exposed routes revealed Paperclip's agent-facing skills documentation, including API paths and authentication conventions or disclosed health information such as deployment mode, version, authentication readiness, bootstrap state, exposure, and feature flags. Paperclip incorporated authentication into general skill routes, added company-access checks to heartbeat issue retrieval, implemented invite-scoped onboarding routes, and reduced the health response for unauthenticated users.
The code tagged with v2026.416.0 includes the necessary fixes, whereas the DNS-rebinding advisory still lacks a patched version entry and NVD retains outdated affected-version metadata in its history.












