🟠 High | Source: The Hacker News
Two vulnerabilities in Paperclip, an open-source AI agent control plane, allow attackers to execute arbitrary commands on servers or developer machines by importing a crafted malicious agent. A third flaw exposes sensitive configuration data and control-plane details via unsecured API routes. These issues are particularly concerning in team environments where agent imports are a routine workflow.
Security Architect’s Take: If your organisation uses Paperclip to orchestrate AI agents, restrict who can import agents and from which sources immediately, and review API route authentication controls. Treat agent imports as a code execution surface and apply the same scrutiny as third-party dependency ingestion.
Original advisory: Paperclip AI Flaws Let Attackers Run Host Commands via Malicious Agent Imports