PoC public Paperclip AI ai-ml Paperclip rce
Paperclip AI Flaws Let Attackers Run Host Commands via Malicious Agent Imports
CVE Tools coverage
Three serious vulnerabilities in the open-source Paperclip AI control plane could allow attackers to run arbitrary commands on a host system or expose sensitive data. The most severe flaw, CVE-2026-41679 (CVSS 10.0), allows unauthenticated attackers to execute commands remotely without prior access. Another vulnerability, GHSA-x8hx-rhr2-9rf7 (CVSS 9.6), exploits default local configurations to launch attacks via DNS rebinding. A third issue involves improperly secured API routes that leak internal details. Paperclip has released a patch in version v2026.416.0, though some advisories still lack full version alignment. Users are urged to upgrade immediately.