Executive brief
Paperclip is an open-source application for managing AI agents in corporate environments. The vulnerability allows an authenticated attacker with an Agent API key to read arbitrary files from the server's filesystem by injecting a malicious file path into agent configuration. An attacker could potentially access sensitive data such as environment files, SSH keys, database credentials, and API tokens, leading to broader compromise of the deployment environment.
Technical details
The vulnerability is a classic path traversal / arbitrary file read issue (CWE-73) in Paperclip's agent adapter configuration handling. The root cause is in packages/adapters/claude-local/src/server/execute.ts, where the code reads instructionsFilePath from attacker-controlled agent configuration via fs.readFile() without path normalization, allowlist validation, or workspace boundary checks. The vulnerable schema (packages/shared/src/validators/agent.ts) permits arbitrary fields inside adapterConfig via z.record(z.unknown()). An authenticated agent can exploit this by: (1) calling PATCH /api/agents/{id} to inject adapterConfig.instructionsFilePath with an absolute path, then (2) triggering agent execution via POST /api/agents/{id}/wakeup, causing the server to attempt reading the attacker-specified file. No administrator privileges are required—only a valid Agent API key. The patch version 2026.416.0 reportedly addresses this issue; affected versions are ≤ v0.3.1.
Affected products
- paperclipai paperclip <= v0.3.1
Timeline
- 2026-04-16: disclosed
- 2026-04-16: patched: Patched in version 2026.416.0