PT-2026-79391 · Paperclip · Paperclip
CVSS v3.1
9.6
Critical
| Vector | AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Paperclip versions prior to 0.3.1
Description
When operating in the default local trusted mode, the software fails to validate Host headers. This allows attackers to perform DNS rebinding—a technique used to bypass the Same-Origin Policy (SOP) by changing the IP address associated with a domain name after the initial DNS lookup—to make authenticated API requests and execute arbitrary commands through the process adapter. This can be triggered if a developer visits a malicious webpage while running the software locally.
Recommendations
Update to version 0.3.1 or later.
Exploit
Fix
Missing Authorization
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Paperclip