@paperclipai/server is vulnerable to Improper Authorization
71
High Risk
HTTP routes that mutate issues and comments, adjust issue-tree automation, and drive workspace lifecycle commands on shared workspaces previously enforced ownership and actor rules inconsistently for peer-agent callers. Before the fix a peer agent could sometimes change another agent's issue objects or issue-tree state, or stop or restart shared workspace runtimes without passing the new permission checks. The patch tightens authorization so those requests fail closed when the caller does not own the target issue or lacks permission for the workspace action.
You are affected if you are using a version that falls within the vulnerable range.
@paperclipai/server is vulnerable to Improper Authorization in versions 2026.318.0 - 2026.416.0.
Upgrade the @paperclipai/server library to the patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

SOC 2Compliant
ISO 27001Compliant