importantSYS.SOURCE: The Hacker News• 2026-08-05T20:44:05+05:30
Critical Vulnerabilities in Paperclip AI Enable Host Command Execution via Malicious Agent Imports
Two critical vulnerabilities in Paperclip AI allow attackers to execute host commands via malicious agent imports and DNS rebinding attacks, while a third exposes sensitive data through misconfigured API routes.
Two security flaws in Paperclip could let attackers execute commands on a network server or a developer's computer. Paperclip is an open-source control plane for teams of artificial intelligence (AI) agents, and both paths rely on importing a malicious agent and starting it.
A third flaw could expose sensitive data and control-plane details through application programming interface (API) routes
*** END OF TRANSMISSION ***