Paperclip: Cross-tenant agent API key IDOR in `/agents/:id/keys` routes allows full victim-company compromise
Critical severity
GitHub Reviewed
Published
Apr 16, 2026
in
paperclipai/paperclip
•
Updated Apr 16, 2026
Give feedback on Dependabot alerts