Sunday, 13 September 2026
8 agent hacks today 7 vs yesterday (1)

Paperclip AI agent orchestrator: unauthenticated and agent-key RCE flaws (CVE-2026-41208/41679)

Two vulnerabilities in @paperclipai/server, a Node.js/React platform that orchestrates a team of AI agents to run a business, allow remote code execution on the server host: one lets an attacker with an Agent API key inject shell commands via a self-updatable adapterConfig provisionCommand field, and another lets an unauthenticated attacker chain six API calls for full RCE on default 'authenticated' mode deployments. Both are fixed in version 2026.416.0.

Disclosed 23 April 2026 · Record updated 13 September 2026

Impact

Remote code execution on the Paperclip server host, including by unauthenticated attackers against network-accessible instances in default configuration; agents could escalate privileges from the agent runtime to the host.

Our coverage

No articles linked to this incident yet.

Sources

  1. nvd.nist.govhttps://nvd.nist.gov/vuln/detail/CVE-2026-41208
  2. nvd.nist.govhttps://nvd.nist.gov/vuln/detail/CVE-2026-41679