Vulnerability threat dossier

CVE-2026-41679

paperclippaperclipai

Paperclip is a Node.js server and React UI that orchestrates a team of AI agents to run a business. Prior to version 2026.416.0, an unauthenticated attacker can achieve full remote code execution on any network-accessible Paperclip instance running in `authenticated` mode with default configuration. No user interaction, no credentials, just the target's address. The chain consists of six API calls. The attack is fully automated, requires no user interaction, and works against the default deployment configuration. Version 2026.416.0 patches the issue.

VTP deterministic threat44.8of 100 · CVSS excluded

VTP analyst assessment

Paperclip unauthenticated remote code execution

AI-assisted analytical recommendationDoes not set factual exploitation state
AI review stateCANDIDATE CREATED
AI priorityHIGH
AI confidence95%
Public exploitation · VTP factCONFIRMED

Assessment

Paperclip before 2026.416.0 permits unauthenticated remote code execution on network-accessible default authenticated-mode instances. The attack chain uses six API calls. ENISA EU KEV lists the CVE as known exploited, and public Nuclei tooling is available.

Why it matters

  • Attackers need only network access to execute code on vulnerable default deployments.
  • Known exploitation makes prompt remediation and exposure reduction necessary.

Evidence

2 record references and 2 source references passed trusted post-response validation. The current deterministic record contains 1 independent evidence group.

Uncertainties

First-party sensor telemetry is active; no disclosure-eligible deterministic observation is currently public for this CVE. This does not mean no activity was observed.

Next watchpoint

If you use Paperclip before 2026.416.0, upgrade immediately and limit network access until remediation completes.

AI baseline history (5)
  1. BASELINE ASSESSED
    Paperclip unauthenticated remote code executiongpt-5.6-terra · low
  2. BASELINE ASSESSED
    Paperclip unauthenticated remote code executiongpt-5.6-terra · low
  3. BASELINE ASSESSED
    Paperclip unauthenticated remote code executiongpt-5.6-terra · low
  4. BASELINE ASSESSED
    Paperclip default-mode unauthenticated remote code executiongpt-5.6-terra · low
  5. BASELINE ASSESSED
    Paperclip default-configuration remote code executiongpt-5.6-sol · high
Technical severityCRITICALCVSS 10.0 · technical context
Public exploitationCONFIRMEDGlobal public evidence
Exploit maturityPOCReliability not implied
EPSS0.1997th percentile · prediction
Evidence confidence95%Strongest independent active claim
VelocitySTABLEMaterial events only
First-party telemetryFirst-party sensor telemetry is active; no disclosure-eligible deterministic observation is currently public for this CVE. This does not mean no activity was observed.
Availability: SENSOR_ONLINE_NO_MATCHING_ACTIVITY · Evidence: UNKNOWN
01

VTP deterministic assessment

Why this matters

  1. 01

    A primary source reports active exploitation.

  2. 02

    A proof of concept is reported; functional reliability is not established.

  3. 03

    EPSS is 0.19; this is predictive context, not exploitation evidence.

  4. 04

    First-party sensor telemetry is active; no disclosure-eligible deterministic observation is currently public for this CVE. This does not mean no activity was observed.

02

Material change ledger

What changed

EXPLOIT TEMPLATE AVAILABLEPublic exploit-oriented template available
03

Claim provenance

Evidence and source independence

4publications detected
4underlying evidence chains

1 primary sources · 0 dependent secondary reports · 2 reports with unresolved independence. Repetition remains visible without multiplying confirmation.

Source claimEXPLOIT TEMPLATE AVAILABLEPUBLIC EXPLOIT TEMPLATE
90%claim confidence
PRIMARYcorpus:NUCLEI:094b33dadcc956ceb637ae5fe7c3a7b02f6e169cACTIVE
Evidence
Source claimACTIVE EXPLOITATIONENISA EU KEV LISTED
95%claim confidence
INDEPENDENTcatalog:enisa-eu-kev:CVE-2026-41679ACTIVE
Evidence
04

Event history

Threat timeline

  1. 14:5916 Sept
    EXPLOIT SOURCE UPDATE

    New exploit-source update

    ProjectDiscovery Nuclei Templates Releases published evidence linked to CVE-2026-41679.

  2. 12:0910 Sept
    EXPLOIT TEMPLATE AVAILABLE

    Public exploit-oriented template available

    ProjectDiscovery nuclei-templates published new or materially changed exploit-oriented tooling for this CVE. This is availability evidence, not evidence of exploitation in the wild.

  3. 00:0017 Aug
    ACTIVE EXPLOITATION

    ENISA EU KEV entry added

    ENISA EU KEV reports known exploitation. VTP imported this historical entry as source baseline. This is public intelligence, not a VTP sensor observation.

05

Original publications

Source record

Nuclei Templates v10.4.9 - Release Notes

New Templates Added: 123 | CVEs Added: 85 | First-time contributions: 15 🔥 Release Highlights 🔥 [ CVE-2026-86207 ] N-able N-central - Authentication Bypass ( @rapid7 , @dhiyaneshdk ) [critical] (vKEV) 🔥 [ CVE-2026-85706 ] GitLab CE/EE <=19.1.7/19.2.5/19.3.1 - Arbitrary File Read ( @flx ) [critical] (kev) (vKEV) 🔥 [ CVE-2026-83548 ] SonicWall SMA1000 WorkPlace - Unauthenticated SSRF to CouchDB ( @rapid7 , @dhiyaneshdk ) [critical] (kev) (vKEV) 🔥 [ CVE-2026-82329 ] JFrog Artifactory Access Blank Join Key Authentication Bypass ( @johnk3r , @pruva ) [critical] (kev) (vKEV) 🔥 [ CVE-2026-82222 ] GiveWP <= 4.16.7.1 - Remote Code Execution (@0x_Akoko, @pdteam ) [critical] (vKEV) 🔥 [ CVE-2026-81578 ] PaperCut NG/MF <=26.0.4 - Unauthenticated ConfigEditor Access via Tapestry Complex-Direct ( @darses , @dhiyaneshdk ) [critical] (kev) (vKEV) 🔥 [ CVE-2026-73570 ] Zimbra Collaboration Suite < 10.1.20 - OS Command Injection (@0x_Akoko, @ritikchaddha ) [high] (kev) (vKEV) 🔥 [ CVE-2026-55040 ] Microsoft SharePoint Server - JWT Authentication Bypass ( @sfewer-r7 , @dhiyaneshdk ) [critical] (kev) (vKEV) 🔥 [ CVE-2026-48558 ] SimpleHelp <=5.5.15 - OIDC JWT Authentication Bypass (@0x_Akoko, @pdteam ) [critical] (kev) (vKEV) 🔥 [ CVE-2026-41948 ] Dify <=1.14.1 - Unauthenticated Plugin Daemon Path Traversal ( @dhiyaneshdk ) [critical] (vKEV) 🔥 [ CVE-2026-32475 ] Elementor Pro <=4.2.1 - Unauthenticated Arbitrary File Upload via Form Handler ( @pdteam ) [critical] (vKEV) 🔥 [ CVE-2026-18963 ] Keycloak < 26.7.2 - Unauthenticated Account Takeover via Reset-Credentials Bypass ( @dhiyaneshdk ) [critical] (vKEV) 🔥 [ CVE-2026-18577 ] N-able N-central < 2026.3.1.10 - Authentication Bypass ( @patrick-threatmate ) [critical] (kev) (vKEV) 🔥 [ CVE-2026-9586 ] Sangoma Switchvox < 8.4.0.2 - Unauthenticated SQL Injection ( @dhiyaneshdk ) [critical] (kev) (vKEV) 🔥 [ CVE-2026-1281 ] Ivanti EPMM <=12.7.0.0 - Unauthenticated Code Injection ( @rxerium ) [critical] (kev) (vKEV) 🔥 [ CVE-2026-0768 ] Langflow <=1.2.x - Unauthenticated Remote Code Execution via validate_code ( @dhiyaneshdk ) [critical] (vKEV) 🔥 [ CVE-2024-1708 ] ConnectWise ScreenConnect <= 23.9.7 - Path Traversal ( @Popy21 ) [high] (kev) (vKEV) 🔥 [ CVE-2023-54391 ] Proxmox VE - Default Credentials with TFA Bypass ( @dhiyaneshdk , @0x_Akoko) [critical] (vKEV) 🔥 [ CVE-2020-10221 ] rConfig <= 3.9.4 - Authenticated OS Command Injection ( @Jayachandran from Securin Labs ( https://securin.io )) [high] (kev) (vKEV) 🔥 [ CVE-2019-11043 ] PHP-FPM Path Info Buffer Underflow - Remote Code Execution ( @prasath from Securin Labs ( https://securin.io )) [critical] (kev) (vKEV) 🔥 [ CVE-2017-7504 ] JBossMQ HTTP Invocation Layer (HTTPServerILServlet) - Unauthenticated Java Deserialization ( @Jayachandran ) [critical] (vKEV) 🔥 What's Changed Bug Fixes Fixed the CVE-2026-41042 template filename so the template loads correctly (PR #17024 , Issue #17022 ). Corrected the filename casing on CVE-2025-14047 .yaml (PR #16994 ). Resolved an unresolved nested payload variable in CVE-2026-4257 that stopped the WordPress Contact Form by Supsystic template running on nuclei v3.11.1 (PR #17039 ). Fixed the matched_feature extractor in CVE-2026-76904 .yaml (PR #16969 ). Corrected the author field in CVE-2026-61511 .yaml (PR #16976 ). Removed six imprecise CVE templates whose proofs of concept were not reliable — CVE-2016-3714 , CVE-2018-10933 , CVE-2018-15708 , CVE-2019-8942 , CVE-2019-17554 and CVE-2020-2555 (PR #16567 ). False Negatives CVE-2021-43798 — the Grafana arbitrary file read template now fires on instances sitting behind an nginx reverse proxy (PR #17185 ). CVE-2018-3760 — restored broken detection on Ruby on Rails local file inclusion using disable-path-automerge and a flow block (PR #17235 ). CVE-2021-34429 — replaced unsafe with disable-path-automerge so the Jetty request path is no longer duplicated (PR #17236 ). CVE-2024-52433 — the My Geo Posts Free template could never match a genuin

CVE-2016-3714CVE-2017-7504CVE-2017-8225CVE-2018-10933CVE-2018-15708CVE-2018-3760CVE-2019-11043CVE-2019-17554CVE-2019-8942CVE-2020-10221CVE-2020-2555CVE-2020-29134CVE-2021-34429CVE-2021-43798CVE-2022-39258CVE-2023-54391CVE-2024-1708CVE-2024-52433CVE-2025-14047CVE-2025-14998CVE-2025-15403CVE-2025-29927CVE-2025-51683CVE-2025-53887CVE-2025-57231CVE-2026-0561CVE-2026-0650CVE-2026-0702CVE-2026-0743CVE-2026-0768CVE-2026-11801CVE-2026-1281CVE-2026-12898CVE-2026-18577CVE-2026-18963CVE-2026-19092CVE-2026-19632CVE-2026-2113CVE-2026-21875CVE-2026-23491CVE-2026-23536CVE-2026-23693CVE-2026-26265CVE-2026-27454CVE-2026-27960CVE-2026-28141CVE-2026-28411CVE-2026-29962CVE-2026-29963CVE-2026-30849CVE-2026-32475CVE-2026-33017CVE-2026-34234CVE-2026-41042CVE-2026-41452CVE-2026-41456CVE-2026-41679CVE-2026-41948CVE-2026-42221CVE-2026-4257CVE-2026-42596CVE-2026-42878CVE-2026-44177CVE-2026-44343CVE-2026-48558CVE-2026-53595CVE-2026-55040CVE-2026-55229CVE-2026-5524CVE-2026-5562CVE-2026-56292CVE-2026-57582CVE-2026-58123CVE-2026-58191CVE-2026-59177CVE-2026-59509CVE-2026-59726CVE-2026-60105CVE-2026-61511CVE-2026-61736CVE-2026-62382CVE-2026-65761CVE-2026-72898CVE-2026-73034CVE-2026-73570CVE-2026-7467CVE-2026-76904CVE-2026-77806CVE-2026-81199CVE-2026-81578CVE-2026-82222CVE-2026-82329CVE-2026-83548CVE-2026-8467CVE-2026-85200CVE-2026-85706CVE-2026-86206CVE-2026-86207CVE-2026-86426CVE-2026-87820CVE-2026-88062CVE-2026-9133CVE-2026-9586
Separate evidence group
Original

Exploit tooling coverage changed for 1 CVE

ProjectDiscovery nuclei-templates recorded exploit-tooling coverage changes for 1 CVE in this pinned revision. 1 have an active availability assertion for this revision. Tooling evidence does not establish exploitation in the wild or successful execution.

CVE-2026-41679
Separate evidence group
Original

ENISA EU KEV catalog membership for CVE-2026-41679

ENISA EU KEV lists this vulnerability as known to be exploited. This is public intelligence, not a VTP sensor observation.

CVE-2026-41679
Separate evidence group
Original

⚡ Weekly Recap: AI Goes Rogue, Metabase 0-Day, MCP Supply-Chain Attacks, and Router Backdoors

A lot of security problems still begin with someone doing a completely normal thing. Cloning a repo. Answering a call. Leaving a box exposed. Trusting the default. That pretty much covers the mood this week. Old bugs are back, supply chains are getting stranger, and some exploit paths are so short you wonder what was supposed to stop them in the first place. That’s only part of it. Here’s

CVE-2013-3821CVE-2025-8943CVE-2026-14869CVE-2026-15307CVE-2026-16496CVE-2026-16498CVE-2026-17583CVE-2026-18236CVE-2026-18497CVE-2026-18556CVE-2026-18577CVE-2026-18830CVE-2026-19137CVE-2026-19149CVE-2026-19154CVE-2026-19157CVE-2026-19170CVE-2026-19172CVE-2026-20267CVE-2026-20272CVE-2026-20303CVE-2026-20304CVE-2026-20310CVE-2026-34348CVE-2026-41679CVE-2026-50481CVE-2026-50515CVE-2026-56162CVE-2026-56181CVE-2026-58048CVE-2026-58072CVE-2026-58073CVE-2026-59115CVE-2026-59774CVE-2026-62830CVE-2026-63508CVE-2026-63913CVE-2026-64531CVE-2026-64561CVE-2026-64564CVE-2026-64638CVE-2026-64650CVE-2026-64651CVE-2026-65400CVE-2026-65667CVE-2026-8496
Separate evidence group
Original
06

Technical vulnerability data

Context, not threat proof

VTP threat score44.8vtp-threat-v1-public
Public exploitation24 / 30
EPSS prediction3.77 / 20
Exploit availability7.5 / 15
Source independence7.5 / 15
Intelligence recency2 / 10
Threat acceleration0 / 10
CVSS technical severityExcluded
CVSS
10 · CRITICAL
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
CWE
CWE-1188, CWE-287, CWE-862
CPE records
2
Deterministic history records
20
Primary technical reference
07

Raw observations

First-party sensor records

First-party sensor telemetry is active; no disclosure-eligible deterministic observation is currently public for this CVE. This does not mean no activity was observed.