Critical vulnerabilities have been disclosed in Paperclip, an AI agent orchestration platform, that could allow attackers to gain administrative access and execute commands on affected servers. The most severe flaw, tracked as CVE-2026-41679, carries a CVSS score of 10.0 and affects network-accessible Paperclip deployments using the default authenticated configuration. Paperclip helps organizations operate autonomous AI agents through companies, tasks, adapters, and configurable workflows. A key feature allows users to import company bundles containing .paperclip.yaml files. These files can define agents, their execution adapters, and commands they run. This turns an apparently simple configuration import into a high-risk...
Read the full article at the source.
Comments (0)
No comments yet. Be the first to comment!