Unauthorized Data Exposure in Hatchet Platform
CVE-2026-63342
6.3MEDIUM
What is CVE-2026-63342?
The Hatchet platform, designed for background task orchestration, has a vulnerability that allows authenticated users to access the event logs of durable tasks not belonging to their own tenant. This is due to the improper implementation of the GET /api/v1/stable/durable-tasks/{durable-task} endpoint prior to version 0.91.1. The logs can disclose sensitive information such as task display names, workflow identifiers, and user messages, which could potentially lead to privacy breaches for affected tenants. The issue has been addressed in version 0.91.1, making it crucial for users to update to this release to safeguard their data.
Affected Version(s)
hatchet < 0.91.1
