Paperclip AI flaws allow host commands via malicious agent imports

Two flaws let attackers execute host commands via malicious agent imports: CVE-2026-41679 (CVSS 10.0, unauthenticated) and GHSA-x8hx-rhr2-9rf7 (CVSS 9.6); a third flaw exposed API data. Rapid7 shipped a Metasploit module, and Oasis Security says "agent configuration must be treated as executable input." Fix in v2026.416.0; no in-the-wild exploitation confirmed.
1 source
Daily brief
Get tomorrow's AI brief in your inbox
More stories today
- CAS creates multi-agent coding factory for Claude Code
- MiniMax H3 update brings 2K, 5× turbo, camera previz
- MiniMax H3 clip chaining keeps motion and audio continuous across joins
- Chinese AI Chipmakers Poised to Gain From Beijing’s Tech Push
- Panther CEO Jack Naglieri: Using AI to build in the open is a good pattern