CVE-2026-41679: Paperclip AI RCE via Malicious Agent Import
Two critical vulnerabilities in Paperclip, an open-source AI agent control plane, allow attackers to execute arbitrary host commands by importing malicious agent configurations — one requiring no authentication whatsoever. A third flaw exposes sensitive data through unenforced API access controls, and Rapid7 has already published a public Metasploit module for the CVSS 10.0 server-side path. The findings underscore a systemic risk in agentic AI platforms: agent configuration is functionally executable code and must be treated as such.