PatchSiren cyber security CVE debrief
CVE-2026-63342 hatchet-dev CVE debrief
CVE-2026-63342 is a vulnerability in Hatchet, a platform for orchestrating background tasks, AI agents, and durable workflows at scale. Prior to version 0.91.1, an authenticated user can read the event log of another tenant's durable task by obtaining the task's UUID, allowing access to sensitive information such as task display names, workflow identifiers, user messages, wait conditions, branching logic, and timing information. This issue is fixed in version 0.91.1.
- Vendor
- hatchet-dev
- Product
- hatchet
- CVSS
- MEDIUM 6.3
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-09-21
- Original CVE updated
- 2026-09-29
- Advisory published
- 2026-09-21
- Advisory updated
- 2026-09-29
Who should care
Defenders responsible for Hatchet deployments should assess exposure and apply the fix to prevent unauthorized access to sensitive task information. This includes verifying exposure by checking Hatchet versions prior to 0.91.1 and applying the fix to prevent potential consequences. Security teams and vulnerability management teams should also review the vulnerability and its impact on their systems.
Why it matters
CVE-2026-63342 allows unauthorized access to sensitive task information in Hatchet deployments prior to version 0.91.1. Defenders should verify exposure and apply the fix to prevent potential consequences.
- Potential unauthorized access to sensitive task information, including task display names, workflow identifiers, user messages, wait conditions, branching logic, and timing information
- Possible impact on task confidentiality and integrity
- Requires verification of exposure and application of the fix to prevent exploitation
Technical summary
The vulnerability is caused by the lack of tenant validation in the GET /api/v1/stable/durable-tasks/{durable-task} endpoint, allowing an authenticated user to read the event log of another tenant's durable task by obtaining the task's UUID. This issue is fixed in version 0.91.1. The vulnerability allows unauthorized access to sensitive task information, including task display names, workflow identifiers, user messages, wait conditions, branching logic, and timing information. Defenders should prioritize verifying exposure and applying the fix.
Defensive priority
Defenders should prioritize verifying exposure and applying the fix, as this vulnerability allows unauthorized access to sensitive task information.
Recommended defensive actions
- Verify exposure by checking if Hatchet versions prior to 0.91.1 are in use
- Apply the fix by upgrading to Hatchet version 0.91.1 or later
- Monitor for potential unauthorized access to task event logs
- Review compensating controls for exposed systems while remediation is scheduled and verified
- Check relevant monitoring, detection, and logs for exposed assets that need extra review
- Track exceptions, retest remediated assets, and close the item only after evidence is documented
- Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up
Evidence notes
The CVE record and NVD entry provide details on the vulnerability, its impact, and the fix. However, additional information about affected deployments and potential consequences is limited. Defenders should verify exposure by checking Hatchet versions prior to 0.91.1 and apply the fix to prevent unauthorized access to sensitive task information. Evidence is based on CVE and NVD entries, with limitations noted.
Sources and references
Verified primary and authoritative sources
-
CVE-2026-63342 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-63342
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-63342 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-63342
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Source reference
Unverified legacy reference
URL: https://github.com/hatchet-dev/hatchet/commit/06c1fe43543e853ea98ecc2e6a575e2b8310bbeb
-
Source reference
Unverified legacy reference
URL: https://github.com/hatchet-dev/hatchet/security/advisories/GHSA-g26x-m427-f48f
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.