
One is about several API endpoints that either lacked authentication or failed to enforce tenant-level authorization, exposing workflow information, skill documentation, and deployment metadata that could aid attackers in reconnaissance or cross-tenant information disclosure.
The other issue (CVSS 9.6) affected Paperclip’s default “local_trusted” deployment mode, where the platform assumed requests reaching localhost originated from trusted software. Oasis demonstrated that a DNS rebinding attack could violate that assumption, allowing an attacker-controlled webpage to communicate with the local Paperclip service and ultimately execute commands on a developer’s machine after importing and triggering a malicious agent.
Paperclip patched the RCE path and the leaking APIs issues in version 2026.416.0 by requiring administrator privileges for new-company imports, strengthening authorization checks across related operations, and adding regression tests.
