CyberRota Analysis
AI-GeneratedHatchet versions prior to 0.91.1 are vulnerable to an authentication bypass due to improper handling of the oauth_state session value, allowing unauthenticated attackers to hijack a victim's session by binding it to an attacker-controlled OAuth identity. This vulnerability primarily affects deployments that have enabled Google, GitHub, or Slack authentication integrations. Organizations using Hatchet should prioritize upgrading to version 0.91.1 to mitigate the risk of session hijacking.
Public Exploit Signal
A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.
Note: these links are listed for security research and verification purposes only.
Original NVD Description
Hatchet is a platform for orchestrating background tasks, AI agents, and durable workflows at scale. Prior to 0.91.1, ValidateOAuthState clears the oauth_state_ session value to an empty string after a successful OAuth callback and later accepts an empty state parameter as equal, allowing an unauthenticated attacker to bind a victim's Hatchet session to an attacker-controlled OAuth identity. Exploitation requires the victim to have completed an OAuth flow in the current session and the deployment to enable auth.google.enabled, auth.github.enabled, or the Slack integration. This issue is fixed in version 0.91.1.