CVE-2026-41208
Last modified
CVE-2026-41208 is a high-severity vulnerability rated 8.8/10 on the CVSS scale. Paperclip is a Node.js server and React UI that orchestrates a team of AI agents to run a business. Versions of @paperclipai/server prior to 2026.416.0 contain a privilege escalation vulnerability that allows an attacker with an Agent API key to execute arbitrary OS commands on the Paperclip server host. EPSS estimates a 0.59% chance of exploitation in the next 30 days.
Description
Paperclip is a Node.js server and React UI that orchestrates a team of AI agents to run a business. Versions of @paperclipai/server prior to 2026.416.0 contain a privilege escalation vulnerability that allows an attacker with an Agent API key to execute arbitrary OS commands on the Paperclip server host. An attacker with an agent credential can escalate privileges from the agent runtime to the Paperclip server host. The vulnerability occurs because agents are allowed to update their own adapterConfig via the /agents/:id API endpoint. The configuration field adapterConfig.workspaceStrategy.provisionCommand is later executed by the server runtime. As a result, an attacker controlling an agent credential can inject arbitrary shell commands which are executed by the Paperclip server during workspace provisioning. This breaks the intended trust boundary between agent runtime configuration and server host execution, allowing a compromised or malicious agent to escalate privileges and run commands on the host system. This vulnerability allows remote code execution on the server host. @paperclipai/server version 2026.416.0 fixes the issue.
Metrics
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Paperclip | Paperclipai | < 2026.416.0 |
References
- https://github.com/paperclipai/paperclip/security/advisories/GHSA-265w-rf2w-cjh4Exploit, Mitigation, Third Party Advisory
- https://github.com/paperclipai/paperclip/security/advisories/GHSA-265w-rf2w-cjh4Exploit, Mitigation, Third Party Advisory
Timeline
- Published
- Last Modified
- Status
- Analyzed
Frequently Asked Questions
What is CVE-2026-41208?
How severe is CVE-2026-41208?
How do I fix CVE-2026-41208?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2026
- CVE-2026-41201CI4MS is a CodeIgniter 4-based CMS skeleton that delivers a …9.1
- CVE-2026-41202CI4MS is a CodeIgniter 4-based CMS skeleton that delivers a …9.4
- CVE-2026-41203CI4MS is a CodeIgniter 4-based CMS skeleton that delivers a …9.4
- CVE-2026-41205Mako is a template library written in Python. Prior to 1.3.1…7.5
- CVE-2026-41206PySpector is a static analysis security testing (SAST) Frame…7.8
- CVE-2026-41207The netty incubator codec.bhttp is a java language binary ht…5.3
- CVE-2026-4121The Kcaptcha plugin for WordPress is vulnerable to Cross-Sit…4.3
- CVE-2026-41211Vite+ is a unified toolchain and entry point for web develop…10
- CVE-2026-41213@node-oauth/oauth2-server is a module for implementing an OA…5.9
- CVE-2026-41217A vulnerability exists in an undisclosed BIG-IP TMOS Shell (…8.3
- CVE-2026-41218When BIG-IP PEM iRules are configured on a virtual server (i…8.7
- CVE-2026-41219An improper sanitization vulnerability exists in the BIG-IP …7.1
Are you affected by CVE-2026-41208?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
