OVERVIEW CVE-2026-41679 is a critical remote code execution vulnerability affecting Paperclip, a Node.js server application with React UI designed to orchestrate AI agent teams for business operations. Versions prior to 2026.416.0 are vulnerable when deployed in authenticated mode with default configuration settings. SEVERITY This vulnerability carries a CVSS 3.1 score of 10.0 (Critical) with a network attack vector requiring no authentication, low complexity, and no user interaction. An unauthenticated attacker can achieve complete remote code execution through a six-step API call chain, resulting in high confidentiality, integrity, and availability impact across the affected system and potentially connected infrastructure. The attack is fully automated and exploitable against any network-accessible Paperclip instance running default configurations. EXPLOITATION STATUS The vulnerability is marked as Active on the Hot List, indicating current community attention and confirmed exploitation activity. While it is not currently listed in the Known Exploited Vulnerabilities (KEV) catalog, the low EPSS score of 0.0017 suggests limited prevalence in active exploitation campaigns at this moment. However, the critical nature of the vulnerability and its inclusion on active threat lists warrant immediate remediation through upgrade to version 2026.416.0 or later.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 2026.416.0CPE matchmatch criteria | cpe:2.3:a:paperclip:paperclipai:*:*:*:*:*:node.js:*:* | ||
< 2026.416.0CPE matchmatch criteria | cpe:2.3:a:paperclip:paperclipai\/server:*:*:*:*:*:node.js:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.