@paperclipai/server is vulnerable to Uncontrolled Resource Consumption
53
Medium Risk
Issue attachment uploads must honor both a process-wide maximum and operator-configured company limits when accepting large multipart bodies. Before the fix the effective ceiling could be applied inconsistently relative to per-company policy as limits flowed into the upload middleware. The patch normalizes and clamps company-specific byte caps through the shared attachment typing and wiring so oversized uploads cannot bypass the intended ceiling as easily.
You are affected if you are using a version that falls within the vulnerable range.
@paperclipai/server is vulnerable to Uncontrolled Resource Consumption in versions 2026.318.0 - 2026.416.0.
Upgrade the @paperclipai/server library to the patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

SOC 2Compliant
ISO 27001Compliant