Paperclip AI flaws let attackers run host commands via agent imports

CVE-2026-41679 (CVSS 10.0) is a server-side flaw requiring no account against network-accessible Paperclip deployments; GHSA-x8hx-rhr2-9rf7 (CVSS 9.6) needs a user to open an attacker-controlled page in default local_trusted mode. Fixed in v2026.416.0; Rapid7 shipped a Metasploit module, and no in-the-wild exploitation was reported as of Aug 5, 2026.
1 source
Daily brief
Get tomorrow's AI brief in your inbox
More stories today
- Paper examines the limitations of current AI evaluation methods
- OnlyHuman filter list removes AI-generated SEO spam from search results
- Qwen tokenizes 330-line code into 1,609 tokens; Gemma needs 4,258
- LifeOS: open-source AI harness for personal growth and work
- MINIMAX video drops Indiana Jones into Mortal Kombat