THREATOPS
THREAT OPSThreat News › Paperclip AI Flaws Let Attackers Run Host Commands via Malicious Agent Imports

Paperclip AI Flaws Let Attackers Run Host Commands via Malicious Agent Imports

lowthehackernewsPublished 2026-08-05

Two security flaws in Paperclip could let attackers execute commands on a network server or a developer's computer. Paperclip is an open-source control plane for teams of artificial intelligence (AI) agents, and both paths rely on importing a malicious agent and starting it.

A third flaw could expose sensitive data and control-plane details through application programming interface (API) routes

MITRE ATT&CK techniques

Original source: https://thehackernews.com/2026/08/paperclip-ai-flaws-let-attackers-run.html