CVE-2026-77087Disclosure

LOWCVSS 9.4 · CRITICAL

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch affected systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

Paperclip before 0.3.1 in default local_trusted mode fails to validate Host headers, allowing attackers to execute arbitrary commands via DNS rebinding. An attacker can craft a malicious webpage that, when visited by a developer running Paperclip locally, uses DNS rebinding to make authenticated API requests and execute commands through the process adapter.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-862

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Threat summary

  • Patch or workaround signal is available
  • 2 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 2 signals
  • Technical details provided in 2 signals
  • Disclosure: 1 classified signal
  • General: 1 classified signal
  • Peaked 1d ago at 1 mentions (2026-08-21); latest day: 1
  • 2 total mentions across 2 days

Deep dive

Activity timeline2 mentions / 2d
00111Mentions · 2026-08-21: 1Mentions · 2026-08-22: 1Patch / Workaround · 2026-08-21: 1Patch / Workaround · 2026-08-22: 1Technical Details · 2026-08-21: 1Technical Details · 2026-08-22: 108-2108-22
Signal classification2 categories
Disclosure
150.0%
General
150.0%
Referenced assets2 URLs
By indicator
Classification over time
DateTotalLabels
2026-08-211
Disclosure1
2026-08-221
General1
Full discourse2 posts
  • CyberAtlas@cyberatlas_ai
    General

    Cyber news updates: CISA has mandated US agencies to patch vulnerabilities in TrueConf software to prevent malware distribution. Full breakdown: http://cyberatlas.ai/bulletin A few other things worth watching this week: Cisco Catalyst SD-WAN zero-day (CVE-2026-20245) allows attackers to manipulate config files NASA/JPL critical vulnerability in spacecraft command software rated CVSS 9.4 SickKids Toronto exposed employee data due to third-party software flaw Apollo confirms breach exposing sensitive personal information via social engineering Critical RCE vulnerability in Paperclip (CVE-2026-77087) has no patch available yet #cybersecurity #news #hack

    Post summary

    The post lists several CVEs and a CISA patch mandate but provides no PoC, exploit, or evidence of live attacks.

    00000205
    27 followersView on X
  • Hugo | DevOps | Cybersecurity 🇱🇻@HugoValters
    Disclosure

    CVE-2026-77087 - Critical RCE in Paperclip <0.3.1 via DNS rebinding. Host header validation flaw allows authenticated API abuse. CVSS 9.6. No patch yet - update when available. #CVE #infosec #Paperclip https://www.valtersit.com/cve/CVE-2026-77087/ #CVE #CVEAlert #infosec #SysAdmin #cybersecurity #Linux #devsecops #devops #developer #sysadmin #100daysofcode #git #github #gitlab #redteam #blueteam #ethicalhacker #ethicalhacking #cybersecurityawareness #cybersecurity #cybersecuritynews #cybersecuritytips #python #hacker #linux #kali #ubuntu #debian #ukraine #spain #ireland #unitedkingdom #canada #finland #estonia #lithuania #ireland #hungary #denmark #norway #malta #mexico #switczerland #iceland #israel

    Post summary

    The tweet discloses a critical RCE vulnerability (CVE‑2026‑77087) in Paperclip <0.3.1 via DNS rebinding, with a CVSS score of 9.6, but no patch or exploit details are presently available.

    0000044
    1.0K followersView on X

Explore more