A critical authorization bypass in Paperclip, tracked as CVE-2026-41679, could let remote attackers self-register, approve a CLI challenge, and gain code execution with the server’s permissions. Oasis Security also reported two additional flaws in Paperclip, including sensitive data disclosure and a DNS rebinding weakness that could enable code execution on developer machines. #Paperclip #CVE-2026-41679 #OasisSecurity
Keypoints
- Paperclip had a critical authorization bypass affecting network-accessible instances.
- Attackers could self-register without email verification and immediately sign in.
- By approving a CLI challenge, attackers could obtain a board API token and access import routes.
- A crafted .paperclip.yaml file could trigger command execution as the Paperclip server process.
- Oasis Security also found a data disclosure bug and a DNS rebinding flaw in local-development mode.
Read More: https://www.securityweek.com/critical-paperclip-flaw-allowed-admin-access-code-execution/