Command injection in Paperclip - #VU141314
Published: August 8, 2026
Vulnerability details
The vulnerability allows a remote user to execute arbitrary code.
The vulnerability exists due to command injection in the workspace runtime service when processing workspace runtime configuration and starting runtime services. A remote user can supply a malicious runtime command through the workspace configuration and trigger the runtime service to start to execute arbitrary code.
User interaction is required to import or load a malicious skill.