Intel

AIKIDO-2026-10713

@paperclipai/shared is vulnerable to Denial of Service (DoS)

Denial of Service (DoS) Pre-CVE
Found by Aikido Intel before public disclosure or CVE publication.
Published May 4, 2026

50

Medium Risk

This Affects:

JS@paperclipai/shared
2026.318.0 - 2026.416.0
Fixed in 2026.428.0
Are you affected? Scan for Free

TL;DR

Issue-related validators accept a request-depth style parameter used while traversing linked issue graphs. Before the fix extremely large values could force disproportionate work during validation or downstream fan-out. The patch clamps the parameter to a fixed maximum and extends tests so pathological depth inputs cannot be used to exhaust CPU or stall request handling.

Who does this affect?

You are affected if you are using a version that falls within the vulnerable range.

Background info

@paperclipai/shared is vulnerable to Denial of Service (DoS) in versions 2026.318.0 - 2026.416.0.

How to fix this

Upgrade the @paperclipai/shared library to the patch version.