Paperclip develops an AI-focused platform and server product characterized by application-layer security issues centered on authentication bypass, OS command injection, insecure initialization defaults, and authorization gaps. These patterns reflect common weaknesses in systems that expose command execution or privilege logic to input-driven contexts; current severity, exploitation, and exposure details are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Paperclip over time
Signals from CVEs in this vendor scope (2 CVEs).
2 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2026-41679CRITICAL Paperclip is a Node.js server and React UI that orchestrates a team of AI agents to run a business. Prior to version 2026.416.0, an unauthenticated attacker can achieve full remote | Apr 23, 2026 | 10.0 | 48 | NO | YES |
CVE-2026-41208HIGH Paperclip is a Node.js server and React UI that orchestrates a team of AI agents to run a business. Versions of @paperclipai/server prior to 2026.416.0 contain a privilege escalati | Apr 23, 2026 | 8.8 | 29 | NO | NO |
Signals from CVEs in this vendor scope (2 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Paperclip.
Media articles that mention a CVE ID that affects a product developed by Paperclip — matched by CVE ID, not by vendor name.