INSPECTING ARCHIVED INTELLIGENCE (OUTDATED VERSION).

Paperclip AI Flaws Allow Unauthenticated Command Execution

| 2026-08-05 15:14 CRITICAL MEDIUM VULNERABILITY DISCLOSURE
Executive Summary
AI-generated
The incident data reveals a critical vulnerability in Paperclip, an agent-facing skill documentation system. The source tagged as Paperclip v2026.416.0 contains the import-authorization fix and hostname-validation guard discussed below, although the DNS-rebinding advisory does not identify a patched version. This means that attackers can exploit CVE-2026-41679 by creating a new company, using an agent with the process adapter, and running the command imported by the agent. The vulnerability requires instance-administrator access for imports targeting a new company and company access for imports targeting an existing one. Paperclip fixed this flaw in v2026.416.0 by requiring authentication to be enabled on both general skill routes and targeted sector API paths. This patch was published by Rapid7, who also released a Metasploit module for CVE-2026-41679 that automates the six-request attack chain. The documented proof of concept has been verified on macOS with Firefox, but other browsers and operating systems may not produce identical results due to differences in user agent strings.
Technical Mitigations AI-generated
* Implement robust access controls and authentication mechanisms to enforce expected access checks on API routes, especially for sensitive data exposure. * Regularly update Paperclip to the latest version (e.g., v2026.416.0) or later to ensure that known vulnerabilities are patched. * Configure agent configuration as executable input by setting up a secure process adapter with proper permissions and validation mechanisms. * Use secure registration processes, such as invitation-based sign-up, to prevent unauthorized access to network-accessible deployments. * Implement API rate limiting and IP blocking to restrict unauthenticated command execution on servers and developers' machines.
Technical Observables Login Required
Indicators of Compromise (IoCs) Protected

Raw threat telemetry, malicious IP addresses, file hashes, and direct VirusTotal correlation are restricted to authenticated users.

pa•••••.yaml
Intelligence Metadata
Actors / Malware / CVEs / Campaigns
CVE-2026-41679CVE-2026-41679
Target & Sectors
Global Scope
Incident Timeline
‎June 2026
Rapid7 published a Metasploit module in June 2026 that automates the CVE-2026-41679 attack chain.
vulnerability CVE-2026-41679
malware Metasploit
organisation CVE-2026
‎August 4
Paperclip AI flaws allow attackers to run host commands via malicious agent imports.
organisation Oasis Security
‎August 5, 2026
The attackers exploited a vulnerability in Paperclip's default open-signup flow to gain unauthorized access.
organisation The Hacker News
attribution Known Exploited
tactic T1588.006 - Vulnerabilities
attribution KEV
organisation CVE-2026-41679
infrastructure 416.0
infrastructure 0.3.1
organisation NVD
infrastructure Macos
organisation Oasis Security's
organisation A Board Key Approved
organisation CLI
organisation Domain Name System
organisation Host
organisation Routes Left Without Their Guards
organisation GHSA-xfqj-r5qw-8g4j (
‎2026.416.0
The attackers exploited a vulnerability in the Paperclip AI, which allowed them to run host commands via malicious agent imports.
‎2026/08/05
The attackers exploited a flaw in Paperclip AI's import-authorization and hostname-validation guards to gain access to sensitive data, including heartbeat information.
organisation GHSA-xfqj-r5qw-8g4j
infrastructure 416.0
organisation DNS
organisation API
organisation CLI
organisation GHSA-x8hx-rhr2-9rf7
organisation CVSS
infrastructure 2026.416.0
organisation Keeper Security
Tactical Metrics
Metrics
infrastructure
‎416.0
Software Version
Metrics
infrastructure
‎Macos
Affected Product
Metrics
infrastructure
‎0.3.1
Software Version
Metrics
infrastructure
‎2026.416.0
Software Version
Intelligence Sources
Infosecurity-Magazine 2026-08-05