OAuth Vulnerability in Hatchet Platform by Hatchet Dev
CVE-2026-61687

7.1HIGH

Key Information:

Status
Vendor
CVE Published:
21 September 2026

What is CVE-2026-61687?

The Hatchet platform, which orchestrates background tasks and AI agents, contains a vulnerability in its OAuth session handling. Prior to version 0.91.1, the ValidateOAuthState function mistakenly clears the oauth_state_ session value after a successful OAuth callback. This flaw allows an unauthenticated attacker to exploit the system by manipulating the OAuth state. If the victim has completed an OAuth flow in the same session and the deployment has specific authentication integrations enabled, the attacker can associate the victim's session with their own OAuth identity. This vulnerability is addressed in version 0.91.1.

Affected Version(s)

hatchet < 0.91.1

References

CVSS V3.1

Score:
7.1
Severity:
HIGH
Confidentiality:
Low
Integrity:
High
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.