PatchSiren

paperclipai CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

CRITICAL paperclipai CVE published 2026-08-21

CVE-2026-77087

Paperclip before 0.3.1 in default local_trusted mode fails to validate Host headers, allowing attackers to execute arbitrary commands via DNS rebinding. This vulnerability enables malicious actors to craft webpages that, when visited by developers running Paperclip locally, can make authenticated API requests and execute commands through the process adapter, potentially leading to unauthorized access and [truncated]