AnalysisCybersecurityAugust 5, 2026

Paperclip AI flaws allow host commands via malicious agent imports

Two flaws let attackers execute host commands via malicious agent imports: CVE-2026-41679 (CVSS 10.0, unauthenticated) and GHSA-x8hx-rhr2-9rf7 (CVSS 9.6); a third flaw exposed API data. Rapid7 shipped a Metasploit module, and Oasis Security says "agent configuration must be treated as executable input." Fix in v2026.416.0; no in-the-wild exploitation confirmed.

1 source

Daily brief

Get tomorrow's AI brief in your inbox

More stories today

Open the live feed