PT-2026-96143 · Hatchet · Hatchet
CVE-2026-63342
·
Published
2026-09-21
·
Updated
2026-09-22
CVSS v3.1
6.3
Medium
| Vector | AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
Hatchet versions prior to 0.91.1
Description
An issue exists in the platform used for orchestrating background tasks, AI agents, and durable workflows. The endpoint 'GET /api/v1/stable/durable-tasks/{durable-task}', implemented by the
listDurableEventLog() function, does not require the target tenant as a parent resource. This allows an authenticated user who possesses another tenant's durable-task UUID to access and read that task's event log. The exposed information may include task display names, workflow identifiers, user messages, wait conditions, branching logic, and timing data.Recommendations
Update to version 0.91.1.
Exploit
Fix
Incorrect Authorization
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Hatchet