Privilege Escalation Vulnerability in Paperclip Server by Paperclip AI
CVE-2026-41208

8.8HIGH

Key Information:

Vendor
CVE Published:
23 April 2026

What is CVE-2026-41208?

The Paperclip server, powered by Node.js and React UI, is susceptible to a privilege escalation vulnerability. This arises from the ability of agents, equipped with an Agent API key, to execute arbitrary operating system commands on the server host. By exploiting the /agents/:id API endpoint, attackers can manipulate their own adapter configurations, particularly the provisionCommand within the adapterConfig. When the server attempts to provision a workspace, it inadvertently executes these malicious commands, thereby breaching the trust boundary. This flaw facilitates remote code execution, effectively allowing an attacker to escalate their privileges on the Paperclip server host.

Affected Version(s)

@paperclipai/server < 2026.416.0

References

CVSS V3.1

Score:
8.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.