Paperclip AI Flaws Let Attackers Run Host Commands via Malicious Agent Imports
The Hacker News
Read full postTwo critical vulnerabilities in the open-source AI control plane Paperclip allow attackers to execute commands on servers or developer machines by importing malicious agents. One flaw requires no authentication and affects network deployments, while another exploits local trusted mode via a malicious webpage. A third issue exposes sensitive data through insufficient API access checks. Users should update to Paperclip v2026.416.0 or later to mitigate these risks.



