Privilege Escalation Vulnerability in Paperclip Server by Paperclip AI
CVE-2026-41208
8.8HIGH
What is CVE-2026-41208?
The Paperclip server, powered by Node.js and React UI, is susceptible to a privilege escalation vulnerability. This arises from the ability of agents, equipped with an Agent API key, to execute arbitrary operating system commands on the server host. By exploiting the /agents/:id API endpoint, attackers can manipulate their own adapter configurations, particularly the provisionCommand within the adapterConfig. When the server attempts to provision a workspace, it inadvertently executes these malicious commands, thereby breaching the trust boundary. This flaw facilitates remote code execution, effectively allowing an attacker to escalate their privileges on the Paperclip server host.
Affected Version(s)
@paperclipai/server < 2026.416.0
