CRITICAL
paperclipai
CVE published 2026-08-21
CVE-2026-77087
Paperclip before 0.3.1 in default local_trusted mode fails to validate Host headers, allowing attackers to execute arbitrary commands via DNS rebinding. This vulnerability enables malicious actors to craft webpages that, when visited by developers running Paperclip locally, can make authenticated API requests and execute commands through the process adapter, potentially leading to unauthorized access and [truncated]