A critical flaw in the Paperclip AI management platform could let an outsider create an account, gain high-level API access, and run commands on the server. Oasis Security said CVE-2026-41679 stems from a missing authorization check in network-accessible Paperclip instances using the default authenticated-mode configuration. Attackers could self-register without email verification, approve their own CLI challenge, obtain board-level API access, and abuse the company import path with a crafted .paperclip.yaml bundle to execute code with the Paperclip service account’s permissions.
Why it matters: Organizations running exposed Paperclip instances should treat this as urgent because it can lead to full server-side command execution and access to data, secrets, and internal services. Patch immediately and review whether local-development setups were exposed to the separate DNS rebinding issue that could let a malicious website run code on a developer machine.
Ionut Arghire
2026.08.06
100% relevant
This article appears to be the first tracked report establishing the Paperclip authorization-bypass and code-execution vulnerability as a distinct security event.
← Back to all stories