CVE-2026-41679
published 2026-04-23CVE-2026-41679: Paperclip is a Node.js server and React UI that orchestrates a team of AI agents to run a business. Prior to version 2026.416.0, an unauthenticated attacker…
PriorityP189critical10CVSS 3.1
AVNACLPRNUINSCCHIHAH
ITWEXPLOITVulnCheck KEV
Exploited in the wild
EPSS
7.36%
94.2th percentile
Paperclip is a Node.js server and React UI that orchestrates a team of AI agents to run a business. Prior to version 2026.416.0, an unauthenticated attacker can achieve full remote code execution on any network-accessible Paperclip instance running in `authenticated` mode with default configuration. No user interaction, no credentials, just the target's address. The chain consists of six API calls. The attack is fully automated, requires no user interaction, and works against the default deployment configuration. Version 2026.416.0 patches the issue.
Affected
4 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| paperclip | paperclipai | < 2026.416.0 | 2026.416.0 |
| paperclip | paperclipai_server | < 2026.416.0 | 2026.416.0 |
| paperclipai | paperclip | < 2026.410.0 | 2026.410.0 |
| paperclipai | paperclipai_server | < 2026.410.0 | 2026.410.0 |
Detection & IOCsextracted from sources · hover to see the quote
- →Monitor for a rapid sequence of six unauthenticated API calls to a Paperclip instance, which is the complete exploit chain for this CVE. ↗
- →Alert on any unauthenticated API requests to Paperclip instances running in 'authenticated' mode — the vulnerability is exploitable with no credentials against the default configuration. ↗
- →A public Metasploit module exists for this CVE targeting Linux/HTTP; presence of exploit traffic matching the module's request patterns should be treated as active exploitation. ↗
- ·The vulnerability is only exploitable against Paperclip instances running in 'authenticated' mode with the default configuration; non-default hardened deployments may not be affected. ↗
- ·The NVD advisory states the patch is in version 2026.416.0, while the Metasploit module references version 2026.410.0 as the boundary — verify the exact patched version against the vendor's official release notes. ↗
CVSS provenance
nvdv3.110.0CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
vulncheck10.0CRITICAL
CVEs like this are exactly what “Exploited This Week” covers.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
No detection rules found.
Nuclei
Paperclip - Remote Code Execution
nuclei·CVSS 10.0
CVE-2026-41679 [CRITICAL] Paperclip - Remote Code Execution
Paperclip - Remote Code Execution
Paperclip < 2026.416.0 contains a remote code execution caused by a chain of six unauthenticated API calls in authenticated mode with default configuration, letting unauthenticated attackers execute arbitrary code remotely, exploit requires network access to the target.
Template:
id: CVE-2026-41679
info:
name: Paperclip - Remote Code Execution
author: theamanrawat,pdteam
severity: critical
description: |
Paperclip < 2026.416.0 contains a remote code execution caused by a chain of six unauthenticated API calls in authenticated mode with default configuration, letting unauthenticated attackers execute arbitrary code remotely, exploit requires network access to the target.
impact: |
Unauthenticated attackers can execute arbitrary code remotely, leading to
Metasploit
Paperclip AI RCE using a chain of six API calls (CVE-2026-41679).
metasploit·CVSS 10.0
CVE-2026-41679 [CRITICAL] Paperclip AI RCE using a chain of six API calls (CVE-2026-41679).
Paperclip AI RCE using a chain of six API calls (CVE-2026-41679).
Paperclip is the operating system for your AI company. You set the goals, hire AI agents as employees, and watch them plan and execute work. Prior to version 2026.410.0, Paperclip allows for an unauthenticated RCE, tracked as CVE-2026-41679. An unauthenticated attacker can achieve full remote code execution on any network-accessible Paperclip instance running in authenticated mode with default configuration. The entire chain is six API calls.
Hackernews
⚡ Weekly Recap: AI Goes Rogue, Metabase 0-Day, MCP Supply-Chain Attacks, and Router Backdoors
blogs_hackernews·2026-08-10
CVE-2026-34348 ⚡ Weekly Recap: AI Goes Rogue, Metabase 0-Day, MCP Supply-Chain Attacks, and Router Backdoors
Home
Threat Intelligence
Vulnerabilities
Cyber Attacks
Webinars
Expert Insights
Awards
Webinars
Awards
Free eBooks
About THN
Jobs
Advertise with us
## ⚡ Weekly Recap: AI Goes Rogue, Metabase 0-Day, MCP Supply-Chain Attacks, and Router Backdoors
A lot of security problems still begin with someone doing a completely normal thing. Cloning a repo. Answering a call. Leaving a box exposed. Trusting the default.
That pretty much covers the mood this week. Old bugs are back, supply chains are getting stranger, and some exploit paths are so short you wonder what was supposed to stop them in the first place.
That’s only part of it. Here’s everything else that made the Monday recap.
## ⚡ Threat of the Week
Anthropic's Model Attempts to Poison Open-Source Project — A new evaluati
Hackernews
Paperclip AI Flaws Let Attackers Run Host Commands via Malicious Agent Imports
blogs_hackernews·2026-08-05·CVSS 10.0
CVE-2026-41679 [CRITICAL] Paperclip AI Flaws Let Attackers Run Host Commands via Malicious Agent Imports
Home
Threat Intelligence
Vulnerabilities
Cyber Attacks
Webinars
Expert Insights
Awards
Webinars
Awards
Free eBooks
About THN
Jobs
Advertise with us
## Paperclip AI Flaws Let Attackers Run Host Commands via Malicious Agent Imports
Two security flaws in Paperclip could let attackers execute commands on a network server or a developer's computer. Paperclip is an open-source control plane for teams of artificial intelligence (AI) agents, and both paths rely on importing a malicious agent and starting it.
A third flaw could expose sensitive data and control-plane details through application programming interface (API) routes that did not enforce the expected access checks.
The more severe server-side path, tracked as CVE-2026-41679 (CVSS score: 10.0), requires no pre-existing
Rapid7
Weekly Metasploit Update: NTLM Relay Priv Esc, MCP Server Integration, Paperclip AI RCE Chain, and more
blogs_rapid7·2026-06-19·CVSS 8.6
CVE-2026-41679 [HIGH] Weekly Metasploit Update: NTLM Relay Priv Esc, MCP Server Integration, Paperclip AI RCE Chain, and more
This week's release includes five new modules, including a full unauthenticated RCE chain for Paperclip AI and a VS Code extension persistence technique. On the post-exploitation side, the new windows/local/ntlm_relay_2_self module coerces the local machine account to authenticate via OpenEncryptedFileRaw (WebDAV), relays that NTLM authentication to a Domain Controller's LDAP service, then uses the resulting LDAP session to write Shadow Credentials and obtain a Kerberos service ticket as Administrator via S4U2Proxy, enabling PsExec back to itself for SYSTEM access.
On the enhancement side, the new MCP server plugin lets AI tools assist operators directly within a running msfconsole instance, and module check codes now return richer detail for users.
## New module content (5)
## Papercli
2026-04-23
Published
Exploited in the wild