@paperclipai/server is vulnerable to Information Disclosure
32
Low Risk
Recovery automation posts explanatory comments on recovery issues when retries fail. Those comments previously echoed raw retry diagnostics so failure blobs from adapters or runtimes could appear verbatim in the issue thread. Before the fix anyone with access to that issue could read operational error material not meant for broad disclosure. The patch redacts or replaces those fragments when composing recovery comments so sensitive failure contents are not exposed in the thread.
You are affected if you are using a version that falls within the vulnerable range.
@paperclipai/server is vulnerable to Information Disclosure in versions 2026.318.0 - 2026.416.0.
Upgrade the @paperclipai/server library to the patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

SOC 2Compliant
ISO 27001Compliant