2026.831.1
5 months ago
4 days ago
Known vulnerabilities in the @paperclipai/ui package. This does not include vulnerabilities belonging to this package’s dependencies.
Snyk's AI Trust Platform automatically finds the best upgrade path and integrates with your development workflows. Secure your code at zero cost.
Fix for free| Vulnerability | Vulnerable Version |
|---|---|
@paperclipai/ui is a Prebuilt Paperclip board UI assets. Affected versions of this package are vulnerable to Missing Authentication for Critical Function in several API endpoints that lack proper authentication checks. An attacker can access sensitive data, perform state-changing operations, and obtain internal configuration details by sending unauthenticated requests to exposed endpoints. How to fix Missing Authentication for Critical Function? Upgrade | <2026.416.0 |
@paperclipai/ui is a Prebuilt Paperclip board UI assets. Affected versions of this package are vulnerable to Insufficient Granularity of Access Control inadequate authorization checks in the Note: This is only exploitable if the application is running in authenticated mode with open signup enabled and at least one other company with agents exists on the instance. How to fix Insufficient Granularity of Access Control? Upgrade | <2026.416.0 |
@paperclipai/ui is a Prebuilt Paperclip board UI assets. Affected versions of this package are vulnerable to Insufficient Verification of Data Authenticity via the Note: This is only exploitable if the attacker is an authenticated board user with access to the target company. How to fix Insufficient Verification of Data Authenticity? Upgrade | <2026.416.0 |
@paperclipai/ui is a Prebuilt Paperclip board UI assets. Affected versions of this package are vulnerable to External Control of File Name or Path via the How to fix External Control of File Name or Path? Upgrade | <2026.416.0 |
@paperclipai/ui is a Prebuilt Paperclip board UI assets. Affected versions of this package are vulnerable to Cross-site Scripting (XSS) in the How to fix Cross-site Scripting (XSS)? Upgrade | <2026.416.0 |
@paperclipai/ui is a Prebuilt Paperclip board UI assets. Affected versions of this package are vulnerable to Missing Authorization via import flow. An attacker can gain remote code execution using company creation endpoint that improperly checks for admin rights in How to fix Missing Authorization? Upgrade | <2026.416.0 |