Critical Paperclip flaws reveal AI agent trust limits
🛡️ Security researchers disclosed multiple vulnerabilities in the open-source AI agent platform Paperclip, including an authorization bypass, exposed APIs, and a DNS rebinding weakness that could lead to remote code execution and developer-machine compromise. Oasis Security detailed how default registration and import behaviors allowed attackers to escalate privileges and execute arbitrary commands by uploading malicious agent configurations. Patches were released in versions 2026.416.0 and 0.3.1 to harden authorization, validate hostnames, and restrict risky imports.
