OVERVIEW CVE-2026-41208 is a privilege escalation vulnerability in Paperclip, a Node.js-based business orchestration platform that coordinates AI agent teams. Affected versions of @paperclipai/server prior to 2026.416.0 allow attackers with valid Agent API credentials to execute arbitrary operating system commands on the Paperclip server host by injecting malicious shell commands into the adapterConfig.workspaceStrategy.provisionCommand field via the /agents/:id API endpoint. SEVERITY The vulnerability carries a CVSS score of 8.8 (HIGH) with a network-based attack vector, low complexity, and low privilege requirements. An attacker with a legitimate agent credential can exploit this flaw without user interaction to achieve complete compromise of the server host, including unauthorized access (confidentiality), modification (integrity), and disruption (availability) of critical systems. The attack breaks the intended trust boundary between agent runtime and server execution contexts. EXPLOITATION STATUS There is no evidence of active exploitation in the wild, with the vulnerability absent from the CISA Known Exploited Vulnerabilities catalog and maintaining inactive status on exploit tracking lists. The low EPSS score of 0.0023 indicates minimal real-world exploitation probability. However, the vulnerability's straightforward exploitation path and high severity warrant immediate patching to version 2026.416.0, particularly for organizations operating Paperclip instances with untrusted or compromised agent credentials.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 2026.416.0CPE matchmatch criteria | cpe:2.3:a:paperclip:paperclipai:*:*:*:*:*:node.js:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.3 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.