Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2026-41679

48
FAUCET Score

OVERVIEW CVE-2026-41679 is a critical remote code execution vulnerability affecting Paperclip, a Node.js server application with React UI designed to orchestrate AI agent teams for business operations. Versions prior to 2026.416.0 are vulnerable when deployed in authenticated mode with default configuration settings. SEVERITY This vulnerability carries a CVSS 3.1 score of 10.0 (Critical) with a network attack vector requiring no authentication, low complexity, and no user interaction. An unauthenticated attacker can achieve complete remote code execution through a six-step API call chain, resulting in high confidentiality, integrity, and availability impact across the affected system and potentially connected infrastructure. The attack is fully automated and exploitable against any network-accessible Paperclip instance running default configurations. EXPLOITATION STATUS The vulnerability is marked as Active on the Hot List, indicating current community attention and confirmed exploitation activity. While it is not currently listed in the Known Exploited Vulnerabilities (KEV) catalog, the low EPSS score of 0.0017 suggests limited prevalence in active exploitation campaigns at this moment. However, the critical nature of the vulnerability and its inclusion on active threat lists warrant immediate remediation through upgrade to version 2026.416.0 or later.

Impacted Technologies

VendorProductVersion(s)CPE
< 2026.416.0CPE matchmatch criteria
cpe:2.3:a:paperclip:paperclipai:*:*:*:*:*:node.js:*:*
< 2026.416.0CPE matchmatch criteria
cpe:2.3:a:paperclip:paperclipai\/server:*:*:*:*:*:node.js:*:*

CVSS Data

CVSS version used by this source: 3.1

10.0CRITICAL

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H

Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
NONE
User Interaction
NONE
Scope
CHANGED
Confidentiality Impact
HIGH
Integrity Impact
HIGH
Availability Impact
HIGH
Exploitability Score
3.9
Impact Score
6.0
CvssVersion
3.1

Exploit Intelligence

EPSS Score
1.97%
Probability of exploitation in next 30 days
EPSS Percentile
78.3%
Percentile rank of EPSS score among Peer Group
As of 2026-07-27
Model: v2026.06.15
Metasploit: Paperclip AI RCE using a chain of six API calls (CVE-2026-41679). · Apr 10, 2026
This CVE's current EPSS score of 0.0197 is in the 67th percentile among its peer group of 36,897 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.

Media Mentions

The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Patch Available

Vendor Patches (3)

npmpatch availablevia ghsa
Product: paperclipaiFixed in: 2026.410.0
npmpatch availablevia ghsa
Product: @paperclipai/serverFixed in: 2026.410.0
github_advisoryworkaround availablevia nvd_reference
View patch

Vendor Advisories (1)

npmGHSA-68qg-g8mg-6pr7critical

paperclip Vulnerable to Unauthenticated Remote Code Execution via Import Authorization Bypass

Apr 10, 2026

References

github.com / paperclipai/paperclip/security/advisories/GHSA-68qg-g8mg-6pr7
ExploitMitigationThird Party Advisory