Security researchers report multiple vulnerabilities in Paperclip, an open-source control plane used to coordinate teams of AI agents. According to reports, two related flaws can allow an attacker to execute operating-system commands on a network server or on a developer’s machine. The attack paths described in the coverage rely on importing a malicious agent and then starting it through the Paperclip control plane. One outlet also highlights that the command-execution impact can be triggered in different deployment modes, including scenarios involving unauthenticated access.
A third flaw is also described. This issue could expose sensitive information through Paperclip’s API routes, including data and control-plane details that should not be accessible. While the outlets differ in emphasis—some foreground the command execution and unauthenticated aspect, others focus on the specific import-and-start mechanism—they broadly agree on the existence of multiple vulnerabilities affecting command execution and potential information disclosure.
The reporting collectively indicates Paperclip users should apply the recommended security updates and review how agent imports and API endpoints are exposed in their environments.