<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-02T15:27:55.668169+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-292783</id>
    <title>EUVD-2026-292783</title>
    <updated>2026-10-02T15:27:55.670580+00:00</updated>
    <content>EUVD-2026-292783</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-292783"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2026-41679</id>
    <title>fkie_cve-2026-41679</title>
    <updated>2026-10-02T15:27:55.670612+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Paperclip is a Node.js server and React UI that orchestrates a team of AI agents to run a business. Prior to version 2026.416.0, an unauthenticated attacker can achieve full remote code execution on any network-accessible Paperclip instance running in `authenticated` mode with default configuration. No user interaction, no credentials, just the target's address. The chain consists of six API calls. The attack is fully automated, requires no user interaction, and works against the default deployment configuration. Version 2026.416.0 patches the issue.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2026-41679"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-68qg-g8mg-6pr7</id>
    <title>GHSA-68qg-g8mg-6pr7 — paperclip Vulnerable to Unauthenticated Remote Code Execution via Import Authorization Bypass</title>
    <updated>2026-10-02T15:27:55.670659+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> npm: paperclipai, npm: @paperclipai/server</p>
<p>## Summary</p>
<p>An unauthenticated attacker can achieve full remote code execution on any network-accessible Paperclip instance running in `authenticated` mode with default configuration. No user interaction, no credentials, just the target's address. The entire chain is six API calls.</p>
<p>I verified every step against the latest version. I have a fully automated PoC script and a video recording available.</p>
<p>Discord: sagi03581</p>
<p>## Steps to Reproduce</p>
<p>The attack chains four independent flaws to escalate from zero access to RCE:</p>
<p>### Step 1: Create an account (no invite, no email verification)</p>
<p>```bash
curl -s -X POST -H "Content-Type: application/json" \
  -d '{"email":"attacker@evil.com","password":"P@ssw0rd123","name":"attacker"}' \
  http://&lt;target&gt;:3100/api/auth/sign-up/email
```</p>
<p>Returns a valid account immediately. No invite token required, no email verification.</p>
<p>This works because `PAPERCLIP_AUTH_DISABLE_SIGN_UP` defaults to `false` in `server/src/config.ts:169-173`:</p>
<p>```typescript
const authDisableSignUp: boolean =
  disableSignUpFromEnv !== undefined
    ? disableSignUpFromEnv === "true"
    : (fileConfig?.auth?.disableSignUp ?? false);   // default: open
```</p>
<p>And email verification is hardcoded off in `server/src/auth/better-auth.ts:89-93`:</p>
<p>```typescript
emailAndPassword: {
  enabled: true,
  requireEmailVerification: false,
  disableSignUp: config.authDisableSignUp,
},
```</p>
<p>The environment variable isn't documented in the deployment guide, so operators don't know it exis…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-68qg-g8mg-6pr7"/>
  </entry>
</feed>
