Junglewise Threat Intelligence

Paperclip server attribution spoofing in approval decisions

Severity: medium · CVSS 4.3 · Published 2026-04-16

Technologies: Paperclip @Paperclipai/Server. Vendors: npm.

Executive brief

Paperclip is an AI agent management platform. A vulnerability in its approval system allows any authorized user to forge the audit trail by claiming an approval or rejection was made by a different user, such as a CEO. This undermines the integrity of the governance process and accountability for financial decisions like agent hiring and budget allocation.

Technical details

The approval-resolution endpoints (`/approvals/:id/approve`, `/reject`, `/request-revision`) in Paperclip server accept a client-supplied `decidedByUserId` field in the request body. The application writes this value directly to the authoritative `approvals.decidedByUserId` database column without verifying it against the authenticated actor's session. An attacker with 'board' level access can use this to attribute their own actions to any other user ID. This forgery also extends to `budget_policies` audit columns when approving agents with monthly budgets. The vulnerability is patched in version 2026.416.0 by deriving the user ID exclusively from the authenticated session.

Affected products

  • Paperclip @paperclipai/server < 2026.416.0

Timeline

  • 2026-04-16: advisory
  • 2026-04-16: patched

References

Related threats