PatchSiren

hatchet-dev CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

MEDIUM hatchet-dev CVE published 2026-09-21

CVE-2026-63342

CVE-2026-63342 is a vulnerability in Hatchet, a platform for orchestrating background tasks, AI agents, and durable workflows at scale. Prior to version 0.91.1, an authenticated user can read the event log of another tenant's durable task by obtaining the task's UUID, allowing access to sensitive information such as task display names, workflow identifiers, user messages, wait conditions, branching logic, [truncated]