Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2026-77087

Опубликовано: 21 авг. 2026
Источник: nvd
CVSS3: 9.6
EPSS Низкий

Описание

Paperclip before 0.3.1 in default local_trusted mode fails to validate Host headers, allowing attackers to execute arbitrary commands via DNS rebinding. An attacker can craft a malicious webpage that, when visited by a developer running Paperclip locally, uses DNS rebinding to make authenticated API requests and execute commands through the process adapter.

EPSS

Процентиль: 34%
0.00396
Низкий

9.6 Critical

CVSS3

Дефекты

CWE-862

Связанные уязвимости

CVSS3: 9.6
github
около 1 месяца назад

Paperclip before 0.3.1 in default local_trusted mode fails to validate Host headers, allowing attackers to execute arbitrary commands via DNS rebinding. An attacker can craft a malicious webpage that, when visited by a developer running Paperclip locally, uses DNS rebinding to make authenticated API requests and execute commands through the process adapter.

EPSS

Процентиль: 34%
0.00396
Низкий

9.6 Critical

CVSS3

Дефекты

CWE-862