Paperclip security patch release for CVE-2026-41679
Security Patch Release
Summary
Hide ▲
Show ▼
Paperclip shipped 2026.416.0 and 0.3.1 to close three disclosed vulnerabilities that could expose data and enable unauthenticated command execution. The release split remediation across authenticated deployments and local mode, with fixes covering CVE-2026-41679 and the DNS rebinding flaw. The patch set reduced risk for both server and developer-machine execution paths.
Related Happenings
Adobe security patch release for CVE-2026-48395
Security Patch Release
H score39
First: 01.08.2026 10:12
Last: 01.08.2026 10:12
Sources 1
About this happening:
Adobe shipped a security update for Adobe Bridge on 2026-08-01 that closes eight critical-rated flaws with risk of privilege escalation and arbitrary code execut...
Adobe security patch release for CVE-2026-48395
Security Patch ReleaseAbout this happening: Adobe shipped a security update for Adobe Bridge on 2026-08-01 that closes eight critical-rated flaws with risk of privilege escalation and arbitrary code execut...
Arista VeloCloud Orchestrator security update for CVE-2026-16812
Security Patch Release
H score55
First: 28.07.2026 01:49
Last: 28.07.2026 01:49
Sources 1
About this happening:
Arista patched CVE-2026-16812, a maximum-severity 10.0 OS command injection flaw in on-premises VeloCloud Orchestrator (VCO), after confirming it is actively...
Arista VeloCloud Orchestrator security update for CVE-2026-16812
Security Patch ReleaseAbout this happening: Arista patched CVE-2026-16812, a maximum-severity 10.0 OS command injection flaw in on-premises VeloCloud Orchestrator (VCO), after confirming it is actively...
VBulletin 6.2.2 security patch release for template-engine flaw
Security Patch Release
H score32
First: 27.07.2026 17:40
Last: 27.07.2026 17:40
Sources 1
About this happening:
vBulletin released security patches for 6.2.1, 6.2.0, and 6.1.6 and shipped 6.2.2 as the fixed build, closing a template-engine remote code execution flaw on s...
VBulletin 6.2.2 security patch release for template-engine flaw
Security Patch ReleaseAbout this happening: vBulletin released security patches for 6.2.1, 6.2.0, and 6.1.6 and shipped 6.2.2 as the fixed build, closing a template-engine remote code execution flaw on s...
Ubuntu snap-confine patch release (CVE-2026-8933)
Security Patch Release
H score34
First: 22.07.2026 13:50
Last: 22.07.2026 13:50
Sources 1
About this happening:
Canonical released snapd updates through the Ubuntu Security Team to fix CVE-2026-8933, a local privilege escalation in snap-confine that can let an unpriv...
Ubuntu snap-confine patch release (CVE-2026-8933)
Security Patch ReleaseAbout this happening: Canonical released snapd updates through the Ubuntu Security Team to fix CVE-2026-8933, a local privilege escalation in snap-confine that can let an unpriv...
Dify security patch release for CVE-2026-41947
Security Patch Release
H score34
First: 22.06.2026 19:13
Last: 22.06.2026 19:13
Sources 1
About this happening:
Dify shipped version 1.14.2 to fix most of the DifyTap vulnerabilities, closing cross-tenant paths that could expose AI chats, uploaded files, and internal API...
Dify security patch release for CVE-2026-41947
Security Patch ReleaseAbout this happening: Dify shipped version 1.14.2 to fix most of the DifyTap vulnerabilities, closing cross-tenant paths that could expose AI chats, uploaded files, and internal API...
Timeline
-
05.08.2026 17:30 1 articles · 2h ago
Oasis Security discloses three Paperclip vulnerabilities
Initial DisclosureOasis Security publishes findings on Paperclip, an open-source AI agent orchestration platform, identifying three vulnerabilities in authenticated deployments and local development mode. CVE-2026-41679 (CVSS 10.0) lets self-registration without email verification and the CLI authorization flow turn a new user into a persistent board-level API key, while other flaws expose sensitive data and enable unauthenticated command execution.
Show sources
- Paperclip AI Flaws Let Unauthenticated Attackers Run Commands — www.infosecurity-magazine.com — 05.08.2026 17:30
-
05.08.2026 17:30 3 articles · 2h ago
Paperclip patches authenticated-mode and local-mode flaws
Mitigation Patch UpdatePaperclip fixes the disclosed vulnerabilities in versions 2026.416.0 and 0.3.1. The authenticated-mode fixes require instance administrator privileges for new-company imports, and the local-mode rebinding flaw adds hostname validation so a malicious webpage cannot use DNS rebinding to reach administrator actions on a developer's machine.
Show sources
- Paperclip AI Flaws Let Unauthenticated Attackers Run Commands — www.infosecurity-magazine.com — 05.08.2026 17:30
- Paperclip AI Flaws Let Unauthenticated Attackers Run Commands — www.infosecurity-magazine.com — 05.08.2026 17:30
- Paperclip AI Flaws Let Attackers Run Host Commands via Malicious Agent Imports — thehackernews.com — 05.08.2026 18:14