Bottom line: Three now-patched Paperclip vulnerabilities (including CVE-2026-41679, CVSS up to 9.6) showed that the platform wrongly treated localhost access and board-level permissions as trustworthy, enabling RCE chains and cross-tenant data exfiltration.
Security researchers at Oasis Security have disclosed three vulnerabilities in the open-source AI agent platform Paperclip that can be chained together to achieve remote code execution, data exfiltration, and compromise of developer machines. All three flaws stem from the same flawed trust assumption in how identity boundaries are handled.
Oasis Security provided CSOonline’s editorial team with details on three vulnerabilities across different Paperclip deployment modes ahead of Wednesday’s disclosure. The most severe flaw, CVE-2026-41679, rated at maximum severity, affects authenticated deployments with default registration settings. An attacker can self-register as an unauthenticated user, approve their own CLI authorization request, and thereby gain persistent board-level API access without requiring separate administrative approval. These permissions are sufficient to exploit a further authorization gap in the company import workflow: while directly creating a new company instance requires administrator rights, importing one previously only required board-level permissions. Since imported company bundles can contain executable agent definitions, a manipulated “.paperclip.yaml” file could be uploaded with a process-based agent that executes arbitrary operating system commands with the privileges of the Paperclip server.
A second class of vulnerabilities affects several API endpoints that either required no authentication or failed to enforce tenant authorization. As a result, workflow information, skill documentation, and deployment metadata were openly accessible, enabling attackers to conduct reconnaissance or exfiltrate information across tenants. The third flaw (CVSS 9.6) affects the default deployment mode “local_trusted,” in which the platform assumes that requests to localhost originate from trustworthy software. Oasis demonstrated that a DNS rebinding attack can defeat this assumption: an attacker-controlled website communicates with the local Paperclip service and, after importing and triggering a manipulated agent, ultimately executes commands on the developer’s machine—a so-called drive-by RCE attack.
Darren Guccione, CEO and co-founder of Keeper Security, who also reviewed the Oasis research, puts the finding into context: an attacker who gains control over an agent configuration doesn’t just get access to data, but the ability to perform privileged actions across any system that agent can reach. For security leaders, this means that AI agent configurations must be treated as executable input, not merely as data—a classification Oasis also explicitly highlights.
All three vulnerabilities have since been fixed. Paperclip closed the RCE chain and the open API endpoints in version 2026.416.0 by requiring administrator rights for company imports, tightening authorization checks on related operations, and adding regression tests. The DNS rebinding flaw was addressed in version 0.3.1 through hostname validation, hardened imports, and restricted high-risk adapters for agent-safe imports. According to CSOonline, Paperclip did not respond to requests for comment.
Source: www.csoonline.com · Published August 5, 2026
Lumi AI News — AI-assisted curation pursuant to Art. 50 EU AI Act. Paraphrasing and classification by Lumi News Pipeline v1.8.3.