Missing Authentication for Critical Function in Paperclip - #VU141312
Published: August 8, 2026
Vulnerability details
The vulnerability allows a remote user to disclose sensitive information and perform unauthorized state-changing operations.
The vulnerability exists due to missing authentication for critical functions in multiple API endpoints when handling requests in authenticated mode. A remote user can send crafted requests to access sensitive data and invoke exposed API functionality without authentication checks.
Exposed endpoints include heartbeat run issue retrieval, CLI authentication challenge creation, skill endpoint access, and deployment configuration disclosure.