PT-2026-79391 · Paperclip · Paperclip

·

CVE-2026-77087

·

Published

2026-08-21

·

Updated

2026-08-21

CVSS v3.1

9.6

Critical

VectorAV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Paperclip versions prior to 0.3.1
Description When operating in the default local trusted mode, the software fails to validate Host headers. This allows attackers to perform DNS rebinding—a technique used to bypass the Same-Origin Policy (SOP) by changing the IP address associated with a domain name after the initial DNS lookup—to make authenticated API requests and execute arbitrary commands through the process adapter. This can be triggered if a developer visits a malicious webpage while running the software locally.
Recommendations Update to version 0.3.1 or later.

Exploit

Fix

Missing Authorization

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-77087
GHSA-X8HX-RHR2-9RF7

Affected Products

Paperclip