CVE-2026-61687
Last modified
CVE-2026-61687 is a high-severity vulnerability rated 7.1/10 on the CVSS scale. Hatchet is a platform for orchestrating background tasks, AI agents, and durable workflows at scale. Prior to 0.91.1, ValidateOAuthState clears the oauth_state_ session value to an empty string after a successful OAuth callback and later accepts an empty state parameter as equal, allowing an unauthenticated attacker to bind a victim's Hatchet session to an attacker-controlled OAuth identity. EPSS estimates a 0.17% chance of exploitation in the next 30 days.
Description
Hatchet is a platform for orchestrating background tasks, AI agents, and durable workflows at scale. Prior to 0.91.1, ValidateOAuthState clears the oauth_state_ session value to an empty string after a successful OAuth callback and later accepts an empty state parameter as equal, allowing an unauthenticated attacker to bind a victim's Hatchet session to an attacker-controlled OAuth identity. Exploitation requires the victim to have completed an OAuth flow in the current session and the deployment to enable auth.google.enabled, auth.github.enabled, or the Slack integration. This issue is fixed in version 0.91.1.
Metrics
Weakness Enumeration
Affected Software
Source: CNA advisory (CVE.org). NVD analysis pending.
| Vendor | Product | Versions |
|---|---|---|
| hatchet-dev | hatchet | < 0.91.1 |
References
Timeline
- Published
- Last Modified
- Status
- Deferred
Frequently Asked Questions
What is CVE-2026-61687?
How severe is CVE-2026-61687?
How do I fix CVE-2026-61687?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2026
- CVE-2026-6168A flaw has been found in TOTOLINK A7000R up to 9.1.0u.6115. …8.8
- CVE-2026-61681Hatchet is a platform for orchestrating background tasks, AI…4.1
- CVE-2026-61682kcp is a Kubernetes-like control plane for form-factors and …9.9
- CVE-2026-61684FastGPT is a knowledge-based AI application platform. In 4.1…8.8
- CVE-2026-61685ReactPress is a publishing system for React developers. Prio…7.5
- CVE-2026-61686SolidInvoice is an open-source invoicing platform. Prior to …7.5
- CVE-2026-61688SolidInvoice is an open-source invoicing platform. Prior to …6.5
- CVE-2026-6169The affiliate-toolkit plugin for WordPress is vulnerable to …7.2
- CVE-2026-61690Grav is a file-based Web platform. Prior to 2.0.1, Grav ZipA…6.5
- CVE-2026-61692Rejected reason: ** REJECT ** DO NOT USE THIS CANDIDATE NUMB…
- CVE-2026-61695Wire provides gRPC and protocol buffers for Android, Kotlin,…7.5
- CVE-2026-61696Forem is open source software for building communities. In v…6.3
Are you affected by CVE-2026-61687?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
