Paperclipai Paperclip vulnerabilities
2 known vulnerabilities affecting paperclipai/paperclip.
Total CVEs
2
CISA KEV
0
Public exploits
1
Exploited in wild
1
Severity breakdown
CRITICAL2
Vulnerabilities
Page 1 of 1
CVE-2026-41679P1CRITICALCVSS 10.0ExploitedPoCfixed in 2026.410.02026-04-23
CVE-2026-41679 [CRITICAL] CWE-287 CVE-2026-41679: Paperclip is a Node.js server and React UI that orchestrates a team of AI agents to run a business.
Paperclip is a Node.js server and React UI that orchestrates a team of AI agents to run a business. Prior to version 2026.416.0, an unauthenticated attacker can achieve full remote code execution on any network-accessible Paperclip instance running in `authenticated` mode with default configuration. No user interaction, no credentials, just the tar
nvd
CVE-2026-77087P2CRITICALCVSS 9.6fixed in 0.3.12026-08-21
CVE-2026-77087 [CRITICAL] CWE-862 CVE-2026-77087: Paperclip before 0.3.1 in default local_trusted mode fails to validate Host headers, allowing attack
Paperclip before 0.3.1 in default local_trusted mode fails to validate Host headers, allowing attackers to execute arbitrary commands via DNS rebinding. An attacker can craft a malicious webpage that, when visited by a developer running Paperclip locally, uses DNS rebinding to make authenticated API requests and execute commands through the proces
nvd