Remote Code Execution Vulnerability in Paperclip by Paperclip AI
CVE-2026-77087

9.4CRITICAL

Key Information:

Status
Vendor
CVE Published:
21 August 2026

What is CVE-2026-77087?

The Paperclip library, prior to version 0.3.1, has a vulnerability in its default local_trusted mode that inadequately validates Host headers. This oversight can be exploited through DNS rebinding techniques, enabling attackers to execute arbitrary commands. By creating a specially crafted malicious webpage, an attacker can manipulate a developer's local environment running Paperclip to send authenticated API requests, thereby executing commands via the process adapter. This presents significant security risks, particularly for developers using this library in local settings.

Affected Version(s)

paperclip 0 < 0.3.1

paperclip 0.3.1

References

CVSS V4

Score:
9.4
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
Unknown

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

sagilayani
.