Skip to content

Paperclip: Cross-tenant agent API key IDOR in `/agents/:id/keys` routes allows full victim-company compromise

Critical severity GitHub Reviewed Published Apr 16, 2026 in paperclipai/paperclip • Updated Apr 16, 2026

No open alerts for this advisory

Give feedback on Dependabot alerts