Security researchers are warning against trust assumptions in AI security with newly detailed flaws affecting the open-source AI agent platform Paperclip that could be chained into remote code execution (RCE), data exposure, and developer-machine compromise.
An Oasis Security , CEO and co-founder of Keeper Security, who has also reviewed Oasis’ research. “An attacker who gains control of an agent configuration doesn’t just access data; they gain the ability to direct privileged action across every system that agent can reach.”
The flaws are now all patched with fixes shipped in versions 2026.416.0 and 0.3.1.
Configuration exploited for code execution
The most severe finding, tracked as input rather than simple data. Paperclip did not immediately respond to CSO’s requests for comments.
Bugs exploited the same underlying assumption
Other than the critical RCE chain, Oasis disclosed two vulnerabilities that highlight the same architectural flaws.
One is about several API endpoints that either lacked authentication or (CVSS 9.6) affected Paperclip’s default “local_trusted” deployment mode, where the platform assumed requests reaching localhost originated from trusted software. Oasis demonstrated that a DNS rebinding attack could violate that assumption, allowing an attacker-controlled webpage to communicate with the local Paperclip service and ultimately execute commands on a developer’s machine after importing and triggering a malicious agent.
Paperclip patched the RCE path and the leaking APIs issues in version 2026.416.0 by requiring administrator privileges for new-company imports, strengthening authorization checks across related operations, and adding regression tests.
The third issue was addressed in Paperclip 0.3.1 by enabling hostname validation, hardening imports, and restricting risky adapters in agent-safe imports.
Guccione argues that traditional access controls are ill-suited for autonomous agents. “The security question is no longer whether a credential is valid at the point of entry,” he said. “It’s whether the agent invoking that credential is doing so within the intended scope, for the intended purpose, under the authority of a human who would sanction that action.”
SOCIAL SHARE CARD GENERATOR