Paperclip 0.3.1 之前的版本在默认的 local_trusted 模式下未能正确验证 Host 头,攻击者可利用 DNS 重绑定技术执行任意命令。攻击者可以构造一个恶意网页,当开发者在本地运行 Paperclip 时访问该页面,页面会通过 DNS 重绑定技术发起经过身份验证的 API 请求,并通过进程适配器执行命令。
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| paperclipai | paperclip | < 0.3.1 |
affected |
0.3.1 |
unaffected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| paperclipai | paperclip | 0 ~ 0.3.1 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No comments yet