Executive brief
Paperclip is an open-source platform for managing AI agents in enterprises. A critical authorization bypass in its control-plane API allows any authenticated user from one company to create, list, and revoke API keys for agents belonging to other companies, then authenticate as those agents to access victim data and workflows. This enables complete cross-tenant compromise where an attacker can impersonate agents in rival organizations and execute any operation they are authorized to perform.
Technical details
The vulnerability is an insecure direct object reference (IDOR) / authorization bypass in the three key-management routes (GET, POST, DELETE) under /agents/:id/keys. The handlers call assertBoard(req) which only verifies the caller is a board-type user, but omit assertCompanyAccess(req, companyId) to verify the caller owns the target agent's company. The POST handler returns the newly-created API key in cleartext. The service layer (agents.ts) does not validate company membership either—it only checks agent existence and status. When used, the returned token sets req.actor.companyId to the victim's company, allowing it to bypass all downstream company-access checks. The DELETE route has an additional flaw: it only requires keyId and ignores the agentId URL parameter, so any authenticated user can revoke any key by its id. Agent UUIDs are widely exposed to board users, and key IDs are disclosed by the GET endpoint, eliminating any ID-guessing difficulty. Fix: call assertCompanyAccess(req, agent.companyId) in all three routes before operating on keys, mirroring the pattern used in adjacent /agents/:id/wakeup and /agents/:id/heartbeat/invoke routes (both of which correctly perform this check). Patched in v2026.416.0.
Affected products
- Paperclip AI Paperclip <= 2026.410.0-canary.1
Timeline
- 2026-04-16: disclosed: Advisory published on GitHub and OSV
- 2026-04-16: patched: Fixed in v2026.416.0