CVE Feed

    Dashboard / CVE / CVE-2026-41679

    CVE-2026-41679

    Paperclip is a Node.js server and React UI that orchestrates a team of AI agents to run a business. Prior to version 2026.416.0, an unauthenticated attacker can achieve full remote code execution on any network-accessible Paperclip instance running in `authenticated` mode with default configuration. No user interaction, no credentials, just the target's address. The chain consists of six API calls. The attack is fully automated, requires no user interaction, and works against the default deployment configuration. Version 2026.416.0 patches the issue.

    Published:Apr 23, 2026
    Last Modified:Apr 28, 2026
    EPS:Apr 23, 2026
    EPSS Score:0.00172
    CVSS Score:10

    Affected Products

    Vendor
    Paperclip
    Product
    Paperclipai
    Vendor
    Paperclip
    Product
    Paperclipai/server
    Vendor
    Paperclip
    Product
    Paperclipai\/server

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High