Paperclip, an open-source control plane for AI agent teams, patched a critical authorization bypass tracked as CVE-2026-41679 that could let a remote attacker self-register on exposed instances, obtain board-level API access, and execute arbitrary commands on the host running the service. The issue affected network-accessible deployments using Paperclip’s default authenticated-mode configuration, where missing authorization checks allowed an attacker to create and approve a CLI challenge, gain a persistent credential, and abuse a company import path that should have been restricted to instance administrators. By importing a crafted .paperclip.yaml file, an attacker could define an agent and command that would be executed by a host-level adapter with the permissions of the Paperclip server process.
Paperclip also fixed two additional flaws reported by Oasis Security: GHSA-x8hx-rhr2-9rf7, a DNS rebinding issue in default local_trusted mode that could enable local command execution on developer machines, and GHSA-xfqj-r5qw-8g4j, which exposed issue data, skill documentation, and deployment details through missing authentication and authorization checks on several API routes. The fixes were released in source tag v2026.416.0, and operators were advised to upgrade to that version or later. Public exploit code has increased risk, including a Rapid7 Metasploit module for CVE-2026-41679, while reporting cited proof-of-concept exploitation but no confirmed active exploitation in the wild at the time of publication.

Track how attackers are adapting to this technology.
4 events from the most recent confirmed update back to the earliest known activity.
Articles published in early August 2026 disclosed technical details of CVE-2026-41679, a critical Paperclip flaw allowing self-registration, board-level API access, malicious agent import, and server-side command execution. The reporting also described a DNS rebinding-based local command-execution path and an API authorization flaw that could expose sensitive data.
Noma Security published a blog post describing 'GitLost,' a technique that allegedly tricked GitHub’s AI agent into leaking contents from private repositories. The post appears to introduce technical details of a distinct security issue affecting GitHub-related AI-assisted workflows.
Rapid7 released a public Metasploit module that automates the six-request attack chain for CVE-2026-41679 in Paperclip. The module provided public proof-of-concept exploitation capability for the critical authorization bypass and command-execution flaw.
Paperclip addressed CVE-2026-41679 by requiring stronger authorization for imports, including instance-administrator access for new-company imports, and applied the same checks to import preview and execution. The same release also added hostname validation protections against DNS rebinding and fixed API routes with missing authentication or authorization checks that could expose sensitive data.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
Follow how adversaries are adapting to this technology, and where it touches your stack today.
5 references tracked. Mallory keeps watching after this page renders.
scworld.com
Open sourcecybersecuritynews.com
Open sourcesecurityweek.com
Open sourcethehackernews.com
Open sourcenoma.security
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.