Vulnerabilities/

paperclip Vulnerable to Unauthenticated Remote Code Execution via Import Authorization Bypass - paperclipai

Severity:
High

Description

An unauthenticated attacker can achieve full remote code execution on any network-accessible Paperclip instance running in authenticated mode with default configuration. No user interaction, no credentials, just the target’s address. The entire chain is six API calls.

I verified every step against the latest version.

Recommendation

Update the paperclipai package to the latest compatible version. Followings are version details:

References

Related Issues

Tags:
npm
paperclipai
Anything's wrong? Let us know Last updated on April 27, 2026