Forensic Summary
Two critical vulnerabilities in Paperclip, an open-source AI agent control plane, allow attackers to execute arbitrary host commands by importing malicious agent configurations — one requiring no authentication whatsoever. A third flaw exposes sensitive data through unenforced API access controls, and Rapid7 has already published a public Metasploit module for the CVSS 10.0 server-side path. The findings underscore a systemic risk in agentic AI platforms: agent configuration is functionally executable code and must be treated as such.
Read the full technical deep-dive on Grid the Grey: https://gridthegrey.com/posts/cve-2026-41679-paperclip-ai-rce-via-malicious-agent-import/
Top comments (0)