Remote Code Execution Vulnerability in Paperclip by Paperclip AI
CVE-2026-77087
9.4CRITICAL
What is CVE-2026-77087?
The Paperclip library, prior to version 0.3.1, has a vulnerability in its default local_trusted mode that inadequately validates Host headers. This oversight can be exploited through DNS rebinding techniques, enabling attackers to execute arbitrary commands. By creating a specially crafted malicious webpage, an attacker can manipulate a developer's local environment running Paperclip to send authenticated API requests, thereby executing commands via the process adapter. This presents significant security risks, particularly for developers using this library in local settings.
Affected Version(s)
paperclip 0 < 0.3.1
paperclip 0.3.1
