Critical Paperclip Flaw Allowed Admin Access, Code Execution

Critical Paperclip Flaw Allowed Admin Access, Code Execution
A critical authorization bypass in Paperclip, tracked as CVE-2026-41679, could let remote attackers self-register, approve a CLI challenge, and gain code execution with the server’s permissions. Oasis Security also reported two additional flaws in Paperclip, including sensitive data disclosure and a DNS rebinding weakness that could enable code execution on developer machines. #Paperclip #CVE-2026-41679 #OasisSecurity

Keypoints

  • Paperclip had a critical authorization bypass affecting network-accessible instances.
  • Attackers could self-register without email verification and immediately sign in.
  • By approving a CLI challenge, attackers could obtain a board API token and access import routes.
  • A crafted .paperclip.yaml file could trigger command execution as the Paperclip server process.
  • Oasis Security also found a data disclosure bug and a DNS rebinding flaw in local-development mode.

Read More: https://www.securityweek.com/critical-paperclip-flaw-allowed-admin-access-code-execution/