SECURITY·중요도 8·2026. 08. 05.·The Hacker News
Paperclip AI Flaws Let Attackers Run Host Commands via Malicious Agent Imports
── KO ──────────────────
Paperclip AI에서 취약점이 발견되어 공격자가 서버 명령어를 실행할 수 있게 됨.
Paperclip AI에 두 가지 보안 취약점이 존재해 공격자가 네트워크 서버나 개발자의 컴퓨터에서 명령어를 실행할 수 있는 가능성이 제기되었습니다. 이 취약점들은 악성 에이전트를 가져오고 시작하는 과정에 의존합니다. 추가적으로, 세 번째 취약점은 애플리케이션 프로그래밍 인터페이스(API) 경로를 통해 민감한 데이터와 제어 평면 세부정보가 노출될 수 있게 합니다.
── EN ──────────────────
Flaws in Paperclip AI allow attackers to execute commands on servers or developer's computers.
Two security flaws in Paperclip AI have been identified that could allow attackers to execute commands on a network server or a developer's computer. Both flaws depend on importing and starting a malicious agent. Additionally, a third flaw could expose sensitive data and control-plane details through application programming interface (API) routes.