OCTOBER 10, 2026
Live Feed
Back to database
Case File

CVE-2026-61687

HIGH · CVSS 7.1 EPSS 0.17% Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-09-21 · Last synced 2026-10-10

CyberRota Analysis

AI-Generated

Hatchet versions prior to 0.91.1 are vulnerable to an authentication bypass due to improper handling of the oauth_state session value, allowing unauthenticated attackers to hijack a victim's session by binding it to an attacker-controlled OAuth identity. This vulnerability primarily affects deployments that have enabled Google, GitHub, or Slack authentication integrations. Organizations using Hatchet should prioritize upgrading to version 0.91.1 to mitigate the risk of session hijacking.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

Detected Signals
exploit

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2026-61687
Severity
HIGH
CVSS
7.1
EPSS
0.17%
GitHub

Original NVD Description

Hatchet is a platform for orchestrating background tasks, AI agents, and durable workflows at scale. Prior to 0.91.1, ValidateOAuthState clears the oauth_state_ session value to an empty string after a successful OAuth callback and later accepts an empty state parameter as equal, allowing an unauthenticated attacker to bind a victim's Hatchet session to an attacker-controlled OAuth identity. Exploitation requires the victim to have completed an OAuth flow in the current session and the deployment to enable auth.google.enabled, auth.github.enabled, or the Slack integration. This issue is fixed in version 0.91.1.