Junglewise Threat Intelligence

Paperclip arbitrary file read via adapterConfig in Claude adapter

Severity: medium · CVSS 6.5 · Published 2026-04-16

Technologies: Paperclip AI Paperclip. Vendors: npm, Paperclip AI.

Executive brief

Paperclip, an AI agent orchestration platform, contains a vulnerability that allows users with an Agent API key to read sensitive files from the server's host filesystem. By modifying their own configuration settings, a malicious or compromised agent can bypass security boundaries to access private data such as SSH keys, database credentials, and environment secrets. This could lead to a broader compromise of the corporate infrastructure or connected services.

Technical details

An arbitrary file read vulnerability exists in Paperclip due to insufficient validation of agent-controlled configuration fields. Attackers with an Agent API key can use the PATCH /api/agents/:id endpoint to inject a malicious filesystem path into the adapterConfig.instructionsFilePath field. During agent execution in packages/adapters/claude-local/src/server/execute.ts, the server uses fs.readFile() on this path without normalization or allowlist validation. This allows an attacker to read any file accessible to the server process, including sensitive configuration and credential files. The issue is fixed in version 2026.416.0.

Affected products

  • paperclipai paperclip < 2026.416.0

Timeline

  • 2026-04-16: advisory: GHSA-3pw3-v88x-xj24 published
  • 2026-04-16: patched: Version 2026.416.0 released

References

Related threats