CRITICAL
9.6 CVE-2026-77087 Published 21 Aug 2026
Paperclip Local DNS Rebinding Vulnerability
Worried this affects one of your servers?
Paperclip, a Ruby gem for handling file uploads, is affected by a vulnerability that allows attackers to execute arbitrary commands via DNS rebinding.
In default local_trusted mode, Paperclip fails to validate Host headers, enabling an attacker to craft a malicious webpage. When a developer running Paperclip locally visits this page, DNS rebinding is used to make authenticated API requests and execute commands through the process adapter.
Reference: CVE-2026-77087 on NVD
← Back to Security News