
Critical Paperclip AI Flaws Enable Unauthenticated RCE and Agent Takeover
A newly disclosed three critical and high-severity vulnerabilities in Paperclip, an open-source control plane used to orchestrate autonomous “zero-human company” AI agents. Documented by Oasis, the most severe flaw allows a completely unauthenticated remote attacker to execute arbitrary commands on the host running the Paperclip server. Tracked as CVE-2026-41679 (CVSS 10.0, GHSA-68qg-g8mg-6pr7), the flaw affects […]
The post Critical Paperclip AI Flaws Enable Unauthenticated RCE and Agent Takeover appeared first on Cyber Security News.