Junglewise Threat Intelligence

CVE-2026-41208: Paperclip: Privilege Escalation via Agent-Controlled workspaceStrategy.provisionCommand Leading to OS Command Execution

CVE-2026-41208 · Severity: high · CVSS 8.8 · Published 2026-04-16

Technologies: @paperclipai/server (npm), Paperclip. Vendors: npm.

Executive brief

Paperclip is an open-source application for managing AI agents. The vulnerability allows an attacker with a valid agent credential to execute arbitrary system commands on the Paperclip server by modifying agent configuration settings. Since agent credentials are designed for automation and are commonly shared with external runtimes and third-party providers, this could allow malicious actors to gain complete control over the server, steal secrets and database credentials, or launch further attacks on connected repositories and infrastructure.

Technical details

The vulnerability is a privilege escalation and remote code execution flaw caused by insufficient input validation and insecure command execution. The root cause lies in the PATCH /api/agents/:id endpoint, which allows agents to modify their own adapterConfig using a permissive validation schema (z.record(z.unknown())). The vulnerable code path in server/src/services/workspace-runtime.ts extracts adapterConfig.workspaceStrategy.provisionCommand and passes it directly to spawn("/bin/sh", ["-c", command]) without any validation, escaping, or allowlist. An attacker with an Agent API key can inject arbitrary shell commands into the provisionCommand field, which are then executed with server privileges during workspace provisioning. The attack vector is network-based and requires only agent API credentials; no administrator access is needed. Successful exploitation enables arbitrary OS command execution, allowing attackers to read environment variables, exfiltrate secrets, modify repositories, access database credentials, and establish reverse shells. Patches are available in version 2026.416.0 and later.

Affected products

  • Paperclip Paperclip <= v0.3.1

Timeline

  • 2026-04-16: disclosed
  • 2026-04-16: patched: Patch version 2026.416.0 released

References

Related threats