OAuth Vulnerability in Hatchet Platform by Hatchet Dev
CVE-2026-61687
7.1HIGH
What is CVE-2026-61687?
The Hatchet platform, which orchestrates background tasks and AI agents, contains a vulnerability in its OAuth session handling. Prior to version 0.91.1, the ValidateOAuthState function mistakenly clears the oauth_state_ session value after a successful OAuth callback. This flaw allows an unauthenticated attacker to exploit the system by manipulating the OAuth state. If the victim has completed an OAuth flow in the same session and the deployment has specific authentication integrations enabled, the attacker can associate the victim's session with their own OAuth identity. This vulnerability is addressed in version 0.91.1.
Affected Version(s)
hatchet < 0.91.1
