Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-gwmj-hf32-5v8v

Опубликовано: 21 авг. 2026
Источник: github
Github: Не прошло ревью
CVSS4: 9.4
CVSS3: 9.6

Описание

Paperclip before 0.3.1 in default local_trusted mode fails to validate Host headers, allowing attackers to execute arbitrary commands via DNS rebinding. An attacker can craft a malicious webpage that, when visited by a developer running Paperclip locally, uses DNS rebinding to make authenticated API requests and execute commands through the process adapter.

Paperclip before 0.3.1 in default local_trusted mode fails to validate Host headers, allowing attackers to execute arbitrary commands via DNS rebinding. An attacker can craft a malicious webpage that, when visited by a developer running Paperclip locally, uses DNS rebinding to make authenticated API requests and execute commands through the process adapter.

EPSS

Процентиль: 33%
0.00396
Низкий

9.4 Critical

CVSS4

9.6 Critical

CVSS3

Дефекты

CWE-862

Связанные уязвимости

CVSS3: 9.6
nvd
около 1 месяца назад

Paperclip before 0.3.1 in default local_trusted mode fails to validate Host headers, allowing attackers to execute arbitrary commands via DNS rebinding. An attacker can craft a malicious webpage that, when visited by a developer running Paperclip locally, uses DNS rebinding to make authenticated API requests and execute commands through the process adapter.

EPSS

Процентиль: 33%
0.00396
Низкий

9.4 Critical

CVSS4

9.6 Critical

CVSS3

Дефекты

CWE-862