Vulnerability  ·  2026-09-22

Hatchet agent orchestrator: OAuth state-clearing session binding bypass (CVSS 7.1)

VulnerabilityHigh impactGlobalCVE-2026-61687
Published 2026-09-21. Because the empty-string state is accepted as a match after the OAuth callback, an attacker can attach a victim's session to an attacker-chosen OAuth identity — an OAuth state-integrity flaw with session-binding consequences (CWE-287/352/384/1275).
Hatchet runs background tasks and durable AI-agent workflows; hijacking an orchestration identity lets an attacker re-route, trigger or observe agent executions and their workflow state, undermining the agent control plane.
ValidateOAuthState clears the oauth_state_ session value to an empty string after a successful OAuth callback and later accepts an empty state parameter as equal. An unauthenticated attacker who can get a victim to be mid-OAuth-flow in their session can bind the victim's Hatchet session to an attacker-controlled OAuth identity, hijacking an agent/orchestrator account.
Hatchet < 0.91.1
Upgrade to Hatchet v0.91.1 (commit f9046418; GHSA-phg3-3g28-wq9v).
NVD CVE-2026-61687Hatchet advisory GHSA-phg3-3g28-wq9v
See this in the live feed Explore related AI security and governance findings — updated every morning.
Open the feed →