CRITICAL 9.4 NVD
CVE-2026-77087
Paperclip before 0.3.1 in default local_trusted mode fails to validate Host headers, allowing attackers to execute arbitrary commands via DNS rebinding. An atta
Paperclip before 0.3.1 in default local_trusted mode fails to validate Host headers, allowing attackers to execute arbitrary commands via DNS rebinding. An attacker can craft a malicious webpage that, when visited by a developer running Paperclip locally, uses DNS rebinding to make authenticated API requests and execute commands through the process adapter.
References
- https://github.com/paperclipai/paperclip/security/advisories/GHSA-x8hx-rhr2-9rf7
- https://www.vulncheck.com/advisories/paperclip-before-remote-code-execution-via-dns-rebind
- https://github.com/paperclipai/paperclip/security/advisories/GHSA-x8hx-rhr2-9rf7
This critical severity vulnerability with a CVSS score of 9.4 was published on 2026-08-21 via NVD.
Risk Timeline
CVE Disclosed2026-08-21 · -1 days ago
Remediation Resources
vulnfeed aggregates 11623 vulnerabilities from NVD, CISA KEV,
Ubuntu, Debian, Red Hat, Kubernetes, Exploit-DB, OSS-Security, GitHub and OpenStack — updated every 4 hours.