{"data":{"id":"0451d51c-cca6-4487-99ef-26775406c4c6","title":"CVE-2026-88978: Hatchet is a platform for orchestrating background tasks, AI agents, and durable workflows at scale. Prior to 0.106.1, t","summary":"Hatchet is a platform for managing background tasks and AI workflows at scale. Before version 0.106.1, a security flaw in the WorkerStatus gRPC polling path (a communication method between processes) allowed an authenticated user from one tenant (a separate customer account) to access another tenant's task records if they knew the task's unique identifier, though this was difficult because identifiers use UUIDv4 (a specific random ID format that's hard to guess).","solution":"This issue is fixed in version 0.106.1.","labels":["security"],"sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-88978","publishedAt":"2026-09-21T16:17:26.010Z","cveId":"CVE-2026-88978","cweIds":["CWE-639","CWE-863"],"cvssScore":"4.3","cvssSeverity":"medium","severity":"medium","attackType":["data_extraction"],"issueType":"vulnerability","affectedPackages":null,"affectedVendors":["HuggingFace"],"affectedVendorsRaw":["Hatchet"],"classifierModel":"claude-haiku-4-5-20251001","classifierPromptVersion":"v3","cvssVector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N","attackVector":"network","attackComplexity":"low","privilegesRequired":"low","userInteraction":"none","exploitMaturity":"unknown","epssScore":0,"patchAvailable":null,"disclosureDate":"2026-09-21T16:17:26.010Z","capecIds":["CAPEC-122"],"crossRefCount":0,"attackSophistication":"moderate","impactType":["confidentiality"],"aiComponentTargeted":"agent","llmSpecific":false,"classifierConfidence":0.85,"researchCategory":null,"atlasIds":null}}