Cyber Resilience
← All news
Corroborated

Paperclip AI Flaws Let Unauthenticated Attackers Run Commands

Our takePaperclip AI has three flaws, including unauthenticated remote command execution and data exposure, across two deployment modes, per Infosecurity. This is a straightforward RCE bug, not an AI-capability story. Patch if you run it.
Sources (3)
What this means for you — Security leader:Patch ServiceNow AI Platform instances immediately; the three CVSS 10.0 flaws allow unauthenticated remote code execution and SQL injection. Self-hosted customers must apply the vendor update now.
What this means for you — Lean IT orgs:If you use ServiceNow, check with your provider that the security update has been applied; these flaws let anyone run commands without logging in. Most teams without ServiceNow can ignore this.
What this means for you — MSP:Confirm that all client ServiceNow instances (hosted and self-hosted) have the security update deployed; three of the flaws are CVSS 10.0 and allow unauthenticated code execution or SQL injection.
What this means for you — Researcher:ServiceNow patched three CVSS 10.0 flaws in its AI Platform that permit unauthenticated command execution and SQL injection in certain configurations; no exploit details are public yet.