Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Fri, 21 Aug 2026 16:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Fri, 21 Aug 2026 15:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Paperclip before 0.3.1 in default local_trusted mode fails to validate Host headers, allowing attackers to execute arbitrary commands via DNS rebinding. An attacker can craft a malicious webpage that, when visited by a developer running Paperclip locally, uses DNS rebinding to make authenticated API requests and execute commands through the process adapter. | |
| Title | Paperclip before 0.3.1 Remote Code Execution via DNS Rebinding | |
| Weaknesses | CWE-862 | |
| References |
| |
| Metrics |
cvssV3_1
|
Subscriptions
No data.
Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2026-08-21T15:51:14.365Z
Reserved: 2026-08-20T10:55:09.093Z
Link: CVE-2026-77087
Updated: 2026-08-21T15:51:00.136Z
Status : Received
Published: 2026-08-21T15:16:47.290
Modified: 2026-08-21T16:18:21.993
Link: CVE-2026-77087
No data.
OpenCVE Enrichment
Updated: 2026-08-21T17:00:04Z