Intel

AIKIDO-2026-10711

@paperclipai/server is vulnerable to Information Disclosure

Information Disclosure Pre-CVE
Found by Aikido Intel before public disclosure or CVE publication.
Published May 4, 2026

32

Low Risk

This Affects:

JS@paperclipai/server
2026.318.0 - 2026.416.0
Fixed in 2026.428.0
Are you affected? Scan for Free

TL;DR

Recovery automation posts explanatory comments on recovery issues when retries fail. Those comments previously echoed raw retry diagnostics so failure blobs from adapters or runtimes could appear verbatim in the issue thread. Before the fix anyone with access to that issue could read operational error material not meant for broad disclosure. The patch redacts or replaces those fragments when composing recovery comments so sensitive failure contents are not exposed in the thread.

Who does this affect?

You are affected if you are using a version that falls within the vulnerable range.

Background info

@paperclipai/server is vulnerable to Information Disclosure in versions 2026.318.0 - 2026.416.0.

How to fix this

Upgrade the @paperclipai/server library to the patch version.