CVSS 10.0 in Paperclip: self-register an account, self-approve a CLI challenge, then import a company YAML that executes shell commands
Oasis Security disclosed CVE-2026-41679 in Paperclip, an AI management platform for running autonomous agents at scale, affecting network-accessible instances in default authenticated mode. The chain requires no invitation and no verified mailbox: register, sign in, create and self-approve a CLI authorization challenge to mint a board API token, then hit the company-import route — which enforced only board-level access while direct company creation required instance admin — with a crafted `.paperclip.yaml` defining an agent that uses a host-level execution adapter. Oasis also reported a DNS-rebinding weakness where local-dev mode trusts everything reaching 127.0.0.1, letting an attacker-controlled webpage run commands on a developer's machine.
Source
↳ Follow the thread