Paperclip Has 92,900 Stars and Ten Security Advisories, Five Rated Critical
Software / analysis
Paperclip Has 92,900 Stars and Ten Security Advisories, Five Rated Critical
The MIT-licensed app that runs teams of AI agents like a company is gaining 3,197 stars a day. Its advisory page lists a drive-by remote code execution against local installs, patched in July.
Paperclip, an open-source app that assigns AI coding agents roles, budgets and reporting lines, had 92,948 GitHub stars on Sept. 29 and ten published security advisories, five of them rated Critical.
GitHub's trending list showed the repository gaining 3,197 stars that day. It was created on March 2, 2026, is MIT-licensed, and reports 15,908 forks. The company behind it is Paperclip Labs, Inc.; its landing page names no founders and lists no pricing.
The question for anyone about to install it is what the software is allowed to touch. The advisory page answers part of that.
What Paperclip does
Paperclip is a Node.js server with a React interface. Each agent, whether Claude Code, Codex, Cursor, a command-line agent or an HTTP bot, gets a role on an org chart, a task queue and a monthly budget. The site shows example budgets of $60, $40, $50 and $30 a month per agent, and says an agent pauses automatically at 100% of its limit.
Agents wake on scheduled "heartbeats" to check for work. Task checkout is atomic, so two agents do not pick up the same ticket. Approval gates and rollback sit on top.
The README says it is "not a chatbot," "not a workflow builder" and "not for single-agent use." It needs Node.js 24.11 or newer. The latest release is v2026.916.1, dated Sept. 21. The site's quickstart is npx paperclipai onboard --yes, which sets up an embedded Postgres database; the README also offers a curl | bash installer at paperclip.ing/install.sh.
The README says telemetry is on by default and can be switched off. It also describes two deployment modes: a trusted local loopback mode and an authenticated mode.
Ten advisories on the record
The project's security advisories page lists ten entries. Eight were published on April 16, one on April 10 and one on July 22. None carries a CVE identifier on that page.
- Critical5 advisories
- High3 advisories
- Moderate2 advisories
Source: GitHub security advisories page for paperclipai/paperclip, accessed 2026-09-29
| Advisory | Severity | Date |
|---|---|---|
| Unauthenticated remote code execution via import authorization bypass (GHSA-68qg-g8mg-6pr7) | Critical | Apr. 10 |
| OS command injection via execution workspace cleanupCommand (GHSA-vr7g-88fq-vhq3) | Critical | Apr. 16 |
| Cross-tenant agent API token minting (GHSA-47wq-cj9q-wpmp) | Critical | Apr. 16 |
| Drive-by RCE against local instances via DNS rebinding (GHSA-x8hx-rhr2-9rf7) | Critical | July 22 |
| Malicious skills able to exfiltrate and destroy all user data (GHSA-w8hx-hqjv-vjcq) | High | Apr. 16 |
The table shows five of the ten. The other Critical entry is a second cross-tenant API key flaw (GHSA-3xx2-mqjm-hg9x). The remaining High entries cover Gmail access inherited by the codex_local adapter, which could send real email, and unauthenticated access to multiple API endpoints. The two Moderate entries are approval attribution spoofing and stored cross-site scripting.
The July entry matters most for the loopback mode. A DNS rebinding attack lets a web page a user merely visits reach a service bound to localhost, so a local-only install is not automatically private.
Why agents make the risk worse
A user on the Cloudron forum, posting as LoudLemur on Sept. 24, wrote that "an agent that reads a hostile ticket or repository could take over the whole Paperclip instance." The same post said the upstream sandbox "relies on Linux namespaces, which Cloudron app containers do not allow," and that any app container there can reach shared database servers directly.
That is one packager's assessment, not an audit. It does describe the shape of the problem: a tool whose job is to feed untrusted text to agents that hold credentials.
Other agent tooling covered on this site sits in the same territory: Nvidia's Sentry is a safety platform for agents, and the OpenRig harness runs Claude Code and Codex together.
Which install path to read first
There are two ways in, and they ask for different amounts of trust. The npx paperclipai onboard --yes route pulls a package from npm and starts an embedded Postgres database on the machine. The curl | bash route runs whatever script paperclip.ing serves at that moment, before any of the advisories can be checked against a version number.
The manual route, git clone followed by pnpm install && pnpm dev, is the only one that lets a reader pin a commit against the release dated Sept. 21. It takes more steps than the two shortcuts.
The April advisories included a flaw rated High, GHSA-w8hx-hqjv-vjcq, titled "Malicious skills able to exfiltrate and destroy all user data." A team that installs third-party skills should read that entry before it does.
What the numbers do not say
The stars and the fork count are interest, not deployments. The advisory count is also not a verdict on quality: a project with 92,948 stars attracts researchers, and published advisories show that reports are being handled. The repository page lists 2,500 issues, while GitHub's API reports 6,000 open items, a count that includes pull requests.
What is missing is any statement about how many of the ten were fixed in v2026.916.1. Each advisory page carries its own patched-version field, and a team should read those before pointing the tool at a repository it does not control.
The next release will be the one to watch: the project has shipped roughly weekly, according to the Cloudron post, and the July advisory is the newest entry on the page.
Sources
More in Software
- 01Ponytail Hits 151,400 GitHub Stars on a Claim of 54% Less Code, Measured by Its AuthorThe plugin tells coding agents to write the minimum. Its benchmark used Claude Haiku 4.5 on one FastAPI template, four runs per ticket, and its tracker has 98 open issues.
- 02OpenDLSS-NR Reimplements Nvidia's DLSS 5 Network in Vulkan, but You Supply the WeightsThe MIT-licensed repository claims byte-for-byte parity with Nvidia's network, yet ships no weights, so the claim cannot be reproduced from the repo alone.
- 03Mozilla Shuts Down Solo AI Website Builder; All Sites Deleted Nov. 30The export ZIP leaves out image source files, Pro subscribers get prorated refunds from Oct. 1, and Mozilla points users to Wix, Squarespace, WordPress, Bolt and Lovable.
- 04IANA Says Example.com's Animated Redesign Is About Bandwidth, Not LooksKim Davies told a Google engineer the page was split to save bytes on automated traffic. Commenters measured 713 bytes of HTML plus 2.15 kB of script and are not convinced.