
Critical Paperclip bugs expose AI agent trust failures
Security researchers are warning against trust assumptions in AI security with newly detailed flaws affecting the open-source AI agent platform Paperclip that could be chained into remote code execution (RCE), data exposure, and developer-machine compromise.
An Oasis Security research shared with CSO ahead of its publication on Wednesday disclosed details of three recent vulnerabilities affecting different Paperclip deployment modes. These include a max-severity authorization bypass issue, multiple improperly protected API endpoints, and a DNS rebinding flaw that enables drive-by RCE against locally deployed instances.
Oasis argues they all stemmed from the same underlying trust assumption P...