The Hacker News reports that flaws in Paperclip, an open-source control plane for AI-agent teams, could let attackers execute commands on servers or developer machines by importing malicious agent configurations; version v2026.416.0 adds import checks and hostname-validation guards.
Paperclip AI Flaws Let Attackers Run Host Commands via Malicious Agent Imports
The Hacker News reports that flaws in Paperclip, an open-source control plane for AI-agent teams, could let attackers execute commands on servers or developer machines by importing malicious agent configurations; version v2026.416.0 adds import checks and hostname-validation guards.
Source: Thehackernews