Vendor
Paperclip versions prior to 0.3.1 are vulnerable to remote code execution due to improper Host header validation when running in 'local_trusted' mode, allowing attackers to leverage DNS rebinding to execute arbitrary commands.