CVE-2026-77087

Paperclip before 0.3.1 in default local_trusted mode fails to validate Host headers, allowing attackers to execute arbitrary commands via DNS rebinding. An attacker can craft a malicious webpage that, when visited by a developer running Paperclip locally, uses DNS rebinding to make authenticated API requests and execute commands through the process adapter.
Configurations

No configuration.

History

No history.

Information

Published : 2026-08-21 15:16

Updated : 2026-08-21 16:18


NVD link : CVE-2026-77087

Mitre link : CVE-2026-77087

CVE.ORG link : CVE-2026-77087


JSON object : View

Products Affected

No product.

CWE
CWE-862

Missing Authorization