Intel

AIKIDO-2026-10710

@paperclipai/server is vulnerable to Improper Authorization

Improper Authorization Pre-CVE
Found by Aikido Intel before public disclosure or CVE publication.
Published May 4, 2026

71

High Risk

This Affects:

JS@paperclipai/server
2026.318.0 - 2026.416.0
Fixed in 2026.428.0
Are you affected? Scan for Free

TL;DR

HTTP routes that mutate issues and comments, adjust issue-tree automation, and drive workspace lifecycle commands on shared workspaces previously enforced ownership and actor rules inconsistently for peer-agent callers. Before the fix a peer agent could sometimes change another agent's issue objects or issue-tree state, or stop or restart shared workspace runtimes without passing the new permission checks. The patch tightens authorization so those requests fail closed when the caller does not own the target issue or lacks permission for the workspace action.

Who does this affect?

You are affected if you are using a version that falls within the vulnerable range.

Background info

@paperclipai/server is vulnerable to Improper Authorization in versions 2026.318.0 - 2026.416.0.

How to fix this

Upgrade the @paperclipai/server library to the patch version.