Summary
Paperclip patched three critical vulnerabilities, including a CVSS 10.0 RCE flaw, that allow attackers to take over AI agent servers and local development machines. The flaws exploit authorization mismatches in company imports and missing authentication on API endpoints.
Take Action:
If you run Paperclip, upgrade it to version 2026.416.0 or later ASAP, keep the management interface off the internet and reachable only from trusted networks, and turn off open self-registration. If any instance was exposed before you patched, assume it was attacked: review imported company configurations, rotate every password, key and token the server could reach, and check connected systems for suspicious activity.
Read the full article on BeyondMachines
This article was originally published on BeyondMachines
Top comments (0)