Executive Summary
In August 2026, multiple critical vulnerabilities were identified in Paperclip, an open-source control plane for AI agent orchestration. The most severe, CVE-2026-41679 (CVSS score: 10.0), allows unauthenticated remote code execution on network-accessible instances running in authenticated mode with default settings. Another flaw, GHSA-x8hx-rhr2-9rf7 (CVSS score: 9.6), enables attackers to execute commands on a developer's machine by exploiting the default local_trusted mode. These vulnerabilities stem from improper authentication and authorization mechanisms, potentially granting attackers full control over affected systems.
The discovery of these flaws underscores the critical importance of securing AI orchestration platforms, especially as their adoption grows. Organizations utilizing Paperclip should promptly update to version 2026.416.0 or later and reassess their deployment configurations to mitigate potential exploitation risks.
Why This Matters Now
The rapid adoption of AI orchestration platforms like Paperclip introduces new attack vectors that can be exploited if not properly secured. Addressing these vulnerabilities is urgent to prevent potential breaches and maintain trust in AI-driven business operations.
Attack Path Analysis
An unauthenticated attacker exploited a vulnerability in Paperclip's default configuration to gain initial access. They escalated privileges by leveraging the import functionality to create a new company and agent. The attacker then moved laterally within the system by executing arbitrary commands through the agent. They established command and control by maintaining persistent access via the compromised agent. Sensitive data was exfiltrated from the system. Finally, the attacker caused significant impact by potentially disrupting services or deploying malware.
Kill Chain Progression
Initial Compromise
Description
An unauthenticated attacker exploited a vulnerability in Paperclip's default configuration to gain initial access.
Related CVEs
CVE-2026-41679
CVSS 10An unauthenticated remote code execution vulnerability in Paperclip allows attackers to execute arbitrary commands on network-accessible instances running in authenticated mode with default configuration.
Affected Products:
paperclipai paperclip – < 2026.416.0
paperclipai @paperclipai/server – < 2026.416.0
Exploit Status:
proof of conceptGHSA-x8hx-rhr2-9rf7
CVSS 9.6A DNS rebinding vulnerability in Paperclip's default local_trusted mode allows attackers to execute arbitrary commands on a developer's machine by tricking them into visiting a malicious webpage.
Affected Products:
paperclipai paperclip – < 2026.416.0
Exploit Status:
proof of conceptGHSA-xfqj-r5qw-8g4j
CVSS 8.3Multiple API endpoints in Paperclip's authenticated mode lack proper authentication, allowing unauthenticated access to sensitive data and state-changing operations.
Affected Products:
paperclipai paperclip – < 2026.416.0
Exploit Status:
proof of concept
MITRE ATT&CK® Techniques
Indirect Command Execution
Command and Scripting Interpreter
System Binary Proxy Execution
Valid Accounts
Application Layer Protocol
Exploit Public-Facing Application
External Remote Services
Remote Services
Potential Compliance Exposure
Mapping incident impact across multiple compliance frameworks.
PCI DSS 4.0 – Ensure all system components and software are protected from known vulnerabilities
Control ID: 6.2
NYDFS 23 NYCRR 500 – Cybersecurity Policy
Control ID: 500.03
DORA – ICT Risk Management Framework
Control ID: Article 5
CISA ZTMM 2.0 – Implement secure application development practices
Control ID: Pillar 3: Applications and Workloads
NIS2 Directive – Security of Network and Information Systems
Control ID: Article 21
Sector Implications
Industry-specific impact of the vulnerabilities, including operational, regulatory, and cloud security risks.
Computer Software/Engineering
Critical supply-chain vulnerabilities in AI agent frameworks enable remote code execution, threatening software development pipelines and deployment infrastructure security.
Information Technology/IT
Paperclip AI flaws expose IT infrastructure to unauthorized command execution via malicious agent imports, requiring immediate patching and deployment configuration reviews.
Computer/Network Security
Security vendors using AI agent platforms face DNS rebinding attacks and authentication bypass vulnerabilities that compromise zero trust segmentation capabilities.
Financial Services
AI agent vulnerabilities threaten financial institutions' compliance frameworks, enabling data exfiltration and unauthorized access to sensitive customer information systems.
Sources
- Paperclip AI Flaws Let Attackers Run Host Commands via Malicious Agent Importshttps://thehackernews.com/2026/08/paperclip-ai-flaws-let-attackers-run.htmlVerified
- Paperclip Vulnerable to Unauthenticated Remote Code Execution via Import Authorization Bypasshttps://github.com/paperclipai/paperclip/security/advisories/GHSA-68qg-g8mg-6pr7Verified
- Drive-by RCE Against Local Paperclip Instances via DNS Rebindinghttps://github.com/paperclipai/paperclip/security/advisories/GHSA-x8hx-rhr2-9rf7Verified
- Unauthenticated Access to Multiple API Endpoints in Authenticated Modehttps://github.com/paperclipai/paperclip/security/advisories/GHSA-xfqj-r5qw-8g4jVerified
- Paperclip Agent Vulnerabilitieshttps://www.oasis.security/blog/paperclip-agent-vulnerabilitiesVerified
Frequently Asked Questions
Cloud Native Security Fabric Mitigations and ControlsCNSF
Aviatrix Zero Trust CNSF is pertinent to this incident as it would likely limit the attacker's ability to move laterally and exfiltrate data by enforcing strict segmentation and identity-based access controls.
Control: Cloud Native Security Fabric (CNSF)
Mitigation: While initial access may still occur, the attacker's ability to exploit the vulnerability could be constrained by limiting unauthorized communications.
Control: Zero Trust Segmentation
Mitigation: The attacker's ability to escalate privileges could be limited by enforcing strict segmentation policies that control access between workloads.
Control: East-West Traffic Security
Mitigation: The attacker's lateral movement could be constrained by monitoring and controlling east-west traffic between workloads.
Control: Multicloud Visibility & Control
Mitigation: The attacker's ability to maintain command and control could be reduced by providing comprehensive visibility and control over multicloud environments.
Control: Egress Security & Policy Enforcement
Mitigation: The attacker's data exfiltration efforts could be limited by enforcing strict egress policies that control outbound data flows.
The attacker's ability to disrupt services or deploy malware could be constrained by limiting their access and movement within the environment.
Impact at a Glance
Affected Business Functions
- AI Agent Management
- Server Administration
- Software Development
Estimated downtime: 7 days
Estimated loss: $50,000
Potential exposure of sensitive data, including application data, source code, credentials, and internal services.
Recommended Actions
Key Takeaways & Next Steps
- • Implement Zero Trust Segmentation to enforce least privilege access and prevent unauthorized agent imports.
- • Deploy Inline IPS (Suricata) to detect and block exploit attempts targeting known vulnerabilities.
- • Utilize Cloud Native Security Fabric (CNSF) for real-time inspection and enforcement of security policies.
- • Establish Multicloud Visibility & Control to monitor and manage security across all cloud environments.
- • Apply Egress Security & Policy Enforcement to control outbound traffic and prevent data exfiltration.



