๐Ÿ” CVE Alert

CVE-2026-63342

MEDIUM 6.3

Hatchet: Cross-Tenant Durable Task Event Log Disclosure via Missing Authorization Check

CVSS Score
6.3
EPSS Score
0.0%
EPSS Percentile
0th

Hatchet is a platform for orchestrating background tasks, AI agents, and durable workflows at scale. Prior to 0.91.1, api-contracts/openapi/paths/v1/workflow-runs/workflow_run.yaml defines the GET /api/v1/stable/durable-tasks/{durable-task} endpoint implemented by listDurableEventLog without requiring the target tenant as a parent resource, allowing an authenticated user who obtains another tenant's durable task UUID to read that task's event log. Disclosed data can include task display names, workflow identifiers, user messages, wait conditions, branching logic, and timing information. This issue is fixed in version 0.91.1.

CWE CWE-863
Vendor hatchet-dev
Product hatchet
Published Sep 21, 2026
Stay Ahead of the Next One

Get instant alerts for hatchet-dev hatchet

Be the first to know when new medium vulnerabilities affecting hatchet-dev hatchet are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

CVSS v3 Breakdown

CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:N/A:N
Attack Vector
Network
Attack Complexity
High
Privileges Required
Low
User Interaction
None
Scope
Changed
Confidentiality
High
Integrity
None
Availability
None

Affected Versions

hatchet-dev / hatchet
< 0.91.1

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
github.com: https://github.com/hatchet-dev/hatchet/security/advisories/GHSA-g26x-m427-f48f github.com: https://github.com/hatchet-dev/hatchet/commit/06c1fe43543e853ea98ecc2e6a575e2b8310bbeb