Paperclip AI flaws let attackers execute arbitrary commands
🛡️ Two critical vulnerabilities in the open-source AI control plane Paperclip allow attackers to import a malicious agent and trigger command execution on either network-accessible servers or local developer machines; a third flaw exposes sensitive control-plane details via inadequately guarded API routes. Vendors have released fixes in the source tagged v2026.416.0, which enforces stricter import permissions and hostname validation, and operators are urged to upgrade and review deployment exposure.
