{"slug": "critical-paperclip-bugs-expose-ai-agent-trust-failures", "title": "Critical Paperclip bugs expose AI agent trust failures", "summary": "Oasis Security disclosed three vulnerabilities in the open-source AI agent platform Paperclip that could be chained into remote code execution, data exposure, and developer-machine compromise, all stemming from a systemic trust assumption flaw in AI agent control planes. The most severe, CVE-2026-41679, allowed unauthenticated users to self-register and obtain board-level API access, leading to arbitrary command execution via malicious agent configuration files. Paperclip patched the flaws in versions 2026.416.0 and 0.3.1, but Darren Guccione, CEO of Keeper Security, warned that attackers gaining control of an agent configuration can direct privileged actions across all connected systems.", "body_md": "Security researchers are warning against trust assumptions in AI security with newly detailed flaws affecting the open-source AI agent platform Paperclip that could be chained into remote code execution (RCE), data exposure, and developer-machine compromise.\n\nAn Oasis Security [research](https://www.oasis.security/blog/paperclip-agent-vulnerabilities) shared with CSO ahead of its publication on Wednesday disclosed details of three recent vulnerabilities affecting different Paperclip deployment modes. These include a max-severity authorization bypass issue, multiple improperly protected API endpoints, and a DNS rebinding flaw that enables drive-by RCE against locally deployed instances.\n\nOasis argues they all stemmed from the same underlying trust assumption Paperclip makes.\n\n“The Paperclip vulnerabilities Oasis Security has disclosed expose something more consequential than a single open-source project: a systemic failure in how AI agent control planes handle identity boundaries,” said [Darren Guccione](https://www.linkedin.com/in/darrenguccione/), CEO and co-founder of Keeper Security, who has also reviewed Oasis’ research. “An attacker who gains control of an agent configuration doesn’t just access data; they gain the ability to direct privileged action across every system that agent can reach.”\n\nThe flaws are now all patched with fixes shipped in versions 2026.416.0 and 0.3.1.\n\nThe most severe finding, tracked as [CVE-2026-41679](https://nvd.nist.gov/vuln/detail/CVE-2026-41679), affected authenticated deployments using Paperclip’s default registration settings.\n\nOasis found that an attacker could begin as an unauthenticated user, self-register for an account, approve their own command-line (CLI) authorization request, and obtain persistent board-level API access without requiring separate administrative approval.\n\nBasically, an attacker on the internet can simply sign up for an account, immediately log in, and use the account to win board-level permissions through the CLI.\n\nThose permissions were sufficient to exploit another authorization mismatch issue in the platform’s company import workflow, Oasis researchers wrote.\n\nIn affected versions, while creating a new company directly required instance administrator privileges, importing a company enforced only board-level permissions. Because imported company bundles could include executable agent definitions, an attacker could upload a malicious “.paperclip.yaml” file specifying a process-based agent, then trigger that agent to execute arbitrary operating system commands under the Paperclip server’s privileges.\n\nOasis warned that this is why AI agent configuration should be treated as [executable](https://www.csoonline.com/article/4199408/ai-agents-can-escape-sandboxes-without-ever-breaking-them.html) input rather than simple data. Paperclip did not immediately respond to CSO’s requests for comments.\n\nOther than the critical RCE chain, Oasis disclosed two vulnerabilities that highlight the same architectural flaws.\n\nOne is about several API endpoints that either lacked authentication or [failed to enforce](https://github.com/advisories/GHSA-xfqj-r5qw-8g4j) tenant-level authorization, exposing workflow information, skill documentation, and deployment metadata that could aid attackers in reconnaissance or cross-tenant information disclosure.\n\nThe other [issue](https://github.com/microsoft/amplifier-app-paperclip/blob/main/.agents/skills/deal-with-security-advisory/SKILL.md) (CVSS 9.6) affected Paperclip’s default “local_trusted” deployment mode, where the platform assumed requests reaching localhost originated from trusted software. Oasis demonstrated that a DNS rebinding attack could violate that assumption, allowing an attacker-controlled webpage to communicate with the local Paperclip service and ultimately execute commands on a developer’s machine after importing and triggering a malicious agent.\n\nPaperclip patched the RCE path and the leaking APIs issues in version 2026.416.0 by requiring administrator privileges for new-company imports, strengthening authorization checks across related operations, and adding regression tests.\n\nThe third issue was addressed in Paperclip 0.3.1 by enabling hostname validation, hardening imports, and restricting risky adapters in agent-safe imports.\n\nGuccione argues that traditional access controls are ill-suited for autonomous agents. “The security question is no longer whether a credential is valid at the point of entry,” he said. “It’s whether the agent invoking that credential is doing so within the intended scope, for the intended purpose, under the authority of a human who would sanction that action.”", "url": "https://wpnews.pro/news/critical-paperclip-bugs-expose-ai-agent-trust-failures", "canonical_source": "https://www.csoonline.com/article/4205630/critical-paperclip-bugs-expose-ai-agent-trust-failures.html", "published_at": "2026-08-05 12:00:17+00:00", "updated_at": "2026-08-05 12:32:01.650313+00:00", "lang": "en", "topics": ["ai-safety", "ai-agents"], "entities": ["Oasis Security", "Paperclip", "CVE-2026-41679", "Darren Guccione", "Keeper Security", "CSO"], "alternates": {"html": "https://wpnews.pro/news/critical-paperclip-bugs-expose-ai-agent-trust-failures", "markdown": "https://wpnews.pro/news/critical-paperclip-bugs-expose-ai-agent-trust-failures.md", "text": "https://wpnews.pro/news/critical-paperclip-bugs-expose-ai-agent-trust-failures.txt", "jsonld": "https://wpnews.pro/news/critical-paperclip-bugs-expose-ai-agent-trust-failures.jsonld"}}