Missing Authorization in Paperclip - #VU141313
Published: August 8, 2026
Vulnerability details
The vulnerability allows a remote attacker to execute arbitrary code.
The vulnerability exists due to improper access control in the local_trusted authentication and hostname validation logic when handling requests from a DNS-rebound origin. A remote attacker can lure a victim into opening a crafted webpage to execute arbitrary code.
User interaction is required to open a malicious webpage, and exploitation is limited to instances running in the default local_trusted mode.