# Critical Authorization Bypass in Paperclip AI Platform Opened the Door to Full Remote Code Execution


## The Threat


Paperclip, an enterprise platform designed to run autonomous AI agents at scale, shipped with a vulnerability so fundamental it's almost disorienting: an unauthenticated attacker on the network could register an account, skip email verification entirely, walk through the platform's CLI authorization flow, and ultimately execute arbitrary commands on the server — all without ever touching an admin credential.


The attack chain, uncovered by Oasis Security and tracked as CVE-2026-41679, hinges on a missing authorization check in the platform's company import path. Paperclip correctly blocked direct company creation to instance administrators, but the import equivalent — which accepts a .paperclip.yaml bundle containing agent definitions and executable commands — only required board-level access. That's a gap you can drive a truck through, and Oasis proved it.


What makes this particularly sharp is how cleanly the privilege escalation flows. An attacker creates an account with no invitation and no verified email. That account session is sufficient to enter Paperclip's CLI authorization flow — a challenge-and-approval process meant to grant persistent board API credentials to command-line clients. The attacker approves their own challenge, walks out with a board API token, and is now one crafted YAML file away from running code as the Paperclip service account. Depending on how that service account is configured, the blast radius extends to application data, secrets injected into agent processes, source repositories, and internal services reachable from the host.


## Severity and Impact


| Field | Detail |

|---|---|

| CVE | CVE-2026-41679 |

| CVSS Score | 10.0 (Critical) |

| Attack Vector | Network |

| Attack Complexity | Low |

| Authentication Required | None |

| Impact | Remote code execution as service account |

| CWE | CWE-862 (Missing Authorization) |


## Affected Products


  • Paperclip — AI agent management platform, all network-accessible instances running default authenticated-mode configuration at time of disclosure

  • Two additional vulnerabilities were patched alongside CVE-2026-41679:


  • Missing authorization on API routes — exposed sensitive data to unauthorized callers
  • DNS rebinding on loopback — in local-development mode, Paperclip binds to 127.0.0.1 and trusts all requests from that address. An attacker-controlled website visited in a browser could exploit this to bypass same-origin protections, reach the local Paperclip API, and execute commands on the developer's machine via a malicious import operation

  • ## Affected Products


  • Paperclip (all versions prior to the patched release)
  • - Network-accessible instances with default authenticated-mode configurations

    - Developer workstations running Paperclip in local-development mode (DNS rebinding vector)


    ## Mitigations


    Update immediately. Paperclip has pushed a fix that applies authorization checks to both the import preview and import execution flows, tightens company scoping, and closes the remaining API authorization gaps.


    For organizations that cannot patch immediately:


  • Restrict network access to Paperclip instances — place them behind a VPN or firewall and eliminate exposure to untrusted networks
  • Disable self-registration if your configuration supports it
  • Audit service account permissions — the RCE payload runs as the Paperclip service account, so least-privilege here limits the blast radius significantly
  • Developer machines: avoid loading untrusted websites while Paperclip's development server is running locally; consider binding the dev server to a non-default address or running in a dedicated, isolated environment

  • ## References


  • [Oasis Security Technical Report (PDF)](https://www.oasissecurity.com) — full exploitation walkthrough
  • Paperclip vendor advisory and patch release

  • ---


    ## HackWire Analysis


    The Paperclip vulnerability is a clean case study in what happens when the AI agent tooling layer inherits web application naivety and no one asks hard questions about the trust model.


    Platforms like Paperclip are categorically different from typical SaaS applications. They don't just hold data — they hold agency. An AI agent platform is wired to external APIs, internal services, credentials, and automation pipelines by design. The service account running the platform is, by intent, a privileged actor. That's the whole product. Achieving RCE on a Paperclip instance isn't equivalent to popping a CMS; it's closer to compromising the automation layer of an organization's entire AI-driven workflow.


    The DNS rebinding issue deserves more attention than it's getting. Developer machines running local Paperclip instances are implicitly trusted by the platform, and that trust can be hijacked by any malicious page opened in the same browser session. This is a class of vulnerability that routinely surfaces in developer tooling — Kubernetes dashboards, local AI sidecars, code assistants — and it remains stubbornly common because local dev mode security is treated as someone else's problem. It isn't.


    Oasis frames the broader concern precisely: agentic workflows distribute both intent and credential across a chain of actors. Logs show the final credential, not the originating user or the responsible agent. In a compromised Paperclip environment, the forensic trail is effectively poisoned from the start. Security teams building incident response playbooks for AI-driven infrastructure need to account for this attribution gap now, before they're dealing with it under pressure.


    The CVSS 10 here is not a formality. Treat it accordingly.


    — HackWire Editorial


    ## Related Coverage


  • Read more in our [Vulnerabilities](https://www.hackwire.news/category/vulnerabilities) coverage
  • Cross-reference with [Breaches](https://www.hackwire.news/category/breaches) and [Malware](https://www.hackwire.news/category/malware)
  • Stay current via the [HackWire homepage](https://www.hackwire.news/)