Critical Paperclip Flaw Allowed Admin Access, Code Execution

https://www.securityweek.com/wp-content/uploads/2025/11/NPM-code-software-development.jpeg

An authorization bypass in Paperclip could have allowed remote attackers to obtain arbitrary code execution with the server’s permissions, Oasis Security reports.

Paperclip is an AI management platform that allows organizations to operate autonomous AI agents at scale. It supports importing companies from portable bundles and YAML files that also define agents and commands they should execute.

Tracked as CVE-2026-41679 (CVSS score of 10), the critical security defect impacted network-accessible Paperclip instances with default authenticated-mode configurations.

A missing authorization check could be exploited to self-register an account without email verification, sign in to the account, create a CLI challenge and approve it, and then deploy an agent by importing a new company.

“A network attacker could create an account and sign in immediately, without an invitation or control of a verified mailbox. That session was enough to enter Paperclip’s CLI authorization flow, a challenge-and-approval process used to authorize a command-line...

Copyright of this story solely belongs to securityweek.com. To see the full text click HERE

Read more

https://www.itvoice.in/wp-content/uploads/2026/08/Copy-of-Redington-2026-08-06T165430.187.jpg

LTM Collaborates with Chainguard to Strengthen Software Supply Chain Security through BlueVerse™ RightLogic

LTM, the Business Creativity partner to the world’s largest enterprises, today announced a strategic collaboration with Chainguard, the trusted source for open source, to strengthen software supply chain security through BlueVerse™ RightLogic, LTM’s cybersecurity assessment and risk assurance framework. The collaboration enables organizations to strengthen security while maintaining