Paperclip - Remote Code Execution
CVE-2026-41679
Verified
Description
Paperclip < 2026.416.0 contains a remote code execution caused by a chain of six unauthenticated API calls in authenticated mode with default configuration, letting unauthenticated attackers execute arbitrary code remotely, exploit requires network access to the target.
Severity
Critical
CVSS Score
10
Exploit Probability
7%
Affected Product
paperclipai
Published Date
August 31, 2026
Template Author
theamanrawat, pdteam
CVE-2026-41679.yaml
10.0Score
CVSS Metrics
CVSS Vector:
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
CVE ID:
cve-2026-41679
CWE ID:
cwe-862, cwe-287, cwe-1188
References
https://github.com/paperclipai/paperclip/security/advisories/GHSA-68qg-g8mg-6pr7https://attackerkb.com/topics/86rSV7hsXi/cve-2026-41679https://www.rapid7.com/db/modules/exploit/linux/http/paperclipai_unauth_rce_cve_2026_41679https://nvd.nist.gov/vuln/detail/CVE-2026-41679https://github.com/bartfroklage/cve-2026-41679
Remediation Steps
Update to version 2026.416.0 or later.