Multiple critical vulnerability flaws in Paperclip AI agent allow for host takeover

Paperclip, an AI-agent platform has been found to have critical flaws, the most critical allowing remote attackers RCE in the Paperclip host server. Attackers can easily use the self-registration without email verification, and abuse a CLI authorization flaw to self-approve API credentials, gaining privilege escalation. An attacker can now import an new workspace and start an agent, now acting as the Paperclip servers OS user. Multiple other flaws in Paperclip all lead to the same issue; trust assumption over actual verification of users. Paperclip has addressed the vulnerabilities and installed defenses, but users on Paperclip should update, restrict open registration, and treat AI agent configuration with care.