OsVault/npm/@paperclipai/server
npm

@paperclipai/server

8 known vulnerabilities · 0 critical · 0 high

GHSA-3xx2-mqjm-hg9x

Paperclip: Cross-tenant agent API key IDOR in `/agents/:id/keys` routes allows full victim-company compromise

Published Apr 16, 2026
GHSA-47wq-cj9q-wpmp

Paperclip: Cross-tenant agent API token minting via missing assertCompanyAccess on /api/agents/:id/keys

Published Apr 16, 2026
GHSA-vr7g-88fq-vhq3

Paperclip: OS Command Injection via Execution Workspace cleanupCommand

Published Apr 16, 2026
GHSA-w8hx-hqjv-vjcq

Paperclip: Malicious skills able to exfiltrate and destroy all user data

Published Apr 16, 2026
GHSA-xfqj-r5qw-8g4j

Paperclip: Unauthenticated Access to Multiple API Endpoints in Authenticated Mode

Published Apr 16, 2026
GHSA-68qg-g8mg-6pr7

paperclip Vulnerable to Unauthenticated Remote Code Execution via Import Authorization Bypass

Published Apr 10, 2026
GHSA-p7mm-r948-4q3q

Paperclip: Approval decision attribution spoofing via client-controlled `decidedByUserId` in paperclip server

Published Apr 16, 2026
GHSA-265w-rf2w-cjh4

Paperclip: Privilege Escalation via Agent-Controlled workspaceStrategy.provisionCommand Leading to OS Command Execution

Published Apr 16, 2026
Check your entire dependency tree at onceRun dependency scan →