Critical CVSS 10.0 flaws in Paperclip AI agent control plane allow unauthenticated code execution

Critical Paperclip AI agent vulnerabilities allow remote code execution

Cybersecurity firm Oasis Security has disclosed three critical vulnerabilities in Paperclip, an open-source control plane used to orchestrate teams of autonomous AI agents. The most severe flaw carries a maximum CVSS score of 10.0, meaning it can be exploited by an unauthenticated attacker with no prior access to the system, resulting in complete compromise of the host server. The disclosure was published on 5 August 2026 and covers issues that allowed remote attackers to execute arbitrary operating system commands simply by importing a malicious AI agent configuration file into the platform.

This matters well beyond the software development teams who typically run orchestration tools like Paperclip. Organisations across every sector, including environmental and technical consultancies, are increasingly experimenting with agentic AI frameworks to automate data parsing, report drafting, laboratory data validation and administrative workflows. Paperclip’s flaws demonstrate a structural weakness common to many early multi-agent architectures: when a control plane treats an imported agent configuration file as trusted instruction rather than executable code, a single malicious import can hand an attacker full privileges on the underlying server or workstation.

For business leaders, in-house counsel and IT risk managers who are being asked to approve pilots of autonomous AI agents, this case is a useful and concrete illustration of what “orchestration layer risk” actually looks like in practice. It is not an abstract AI safety concern. It is a conventional remote code execution vulnerability, arising because identity verification and privilege separation were absent at the point where new agents are onboarded into the system.

How the flaws work: CVE-2026-41679 and the DNS rebinding attack

The critical vulnerability, tracked as CVE-2026-41679, received a CVSS score of 10.0, the highest possible severity rating. Oasis Security found that Paperclip permitted unverified self-registration, meaning a new user could register an account and auto-approve command line interface credential challenges without any administrator gatekeeping. This self-registration flaw let an unauthenticated actor grant themselves board-level API permissions, the highest tier of administrative access within the platform.

Once an attacker held those elevated permissions, they could exploit Paperclip’s company import route to upload an agent configuration built around the platform’s built-in “process adapter.” This adapter is designed to execute commands as child processes, but it does so under the host server’s own operating system privileges. In effect, importing a crafted agent file was equivalent to handing an outside attacker a root-level command shell on the server, with no authentication step in between.

A second flaw, catalogued as GHSA-x8hx-rhr2-9rf7 with a CVSS score of 9.6, targeted local developer deployments rather than production servers. This vulnerability relied on DNS rebinding, a technique where a malicious external webpage manipulates DNS resolution to bypass the browser’s same-origin policy. Using this method, an attacker could trick a developer’s browser into believing a malicious agent was a trusted local resource, waking dormant agents on the local Paperclip instance and triggering command execution on that workstation. Because many developers run these control planes locally during testing, this attack path extended the blast radius from production infrastructure to individual staff laptops.

Both issues have been resolved in Paperclip version 2026.416.0. The fix restricts company and agent configuration imports exclusively to verified instance administrators and adds strict hostname validation to close off the DNS rebinding pathway. Organisations running earlier versions of Paperclip in production or development environments remain exposed until they patch to this release. Keeper Security CEO Darren Guccione described the underlying problem succinctly, stating that the vulnerabilities expose “a systemic failure in how AI agent control planes handle identity boundaries,” and noted that controlling an agent’s configuration effectively grants an attacker direct, privileged execution across every corporate system that agent is connected to.

thehackernews.com
Image source: thehackernews.com

Australian context

Paperclip is open-source infrastructure rather than an Australian-specific product, so there is no direct regulatory instrument in Australia that governs its use. However, the underlying risk pattern is directly relevant to Australian organisations, including environmental consultancies, engineering firms and property groups that are piloting agentic AI to speed up document review, site data processing or client reporting workflows. The Australian Cyber Security Centre has repeatedly flagged supply chain and third-party software risk as a priority area, and orchestration platforms for autonomous agents sit squarely within that risk category because they typically hold broad, standing access to internal systems, file stores and sometimes client environments.

For businesses subject to the Privacy Act 1988 and the Australian Privacy Principles, an unauthenticated remote code execution flaw of this severity in an AI orchestration tool raises immediate questions about data breach notification obligations under the Notifiable Data Breaches scheme, particularly where the compromised server hosts client data, site assessment records or personal information. Any organisation that has deployed Paperclip, or a similar unauthenticated self-registration model in another agentic AI platform, needs to assess whether affected systems processed personal or commercially sensitive information during the exposure window.

Australian firms evaluating agentic AI vendors should treat this disclosure as a benchmark case for procurement due diligence. Vendor security questionnaires and contractual warranties should now explicitly address how agent configuration imports are authenticated, how administrative privileges are separated within the orchestration layer, and how quickly critical patches are made available and applied once a vulnerability is disclosed.

References and related sources

How iEnvi can help

iEnvi integrates technology and data-driven approaches into environmental consulting. We monitor AI and technology developments that affect how environmental professionals deliver services to clients.


This is an iEnvi Machete news summary. Prepared by iEnvi to summarise the source article for environmental professionals tracking AI, data, and technology developments that affect consulting and project delivery.

Published: 06 Aug 2026

Need advice on this topic? Speak to an iEnvi expert at info@ienvi.com.au or 1300 043 684, or contact us online.

Need advice on this issue? iEnvi provides practical, senior-led environmental consulting across contaminated land, remediation, ecology and environmental risk.

Environmental due diligence Talk to iEnvi