{"data":{"id":"2c5ab53c-fb2b-4c83-8dc0-db1ca130a7ec","title":"CVE-2026-61681: Hatchet is a platform for orchestrating background tasks, AI agents, and durable workflows at scale. Prior to 0.91.1, th","summary":"Hatchet (a platform for running background tasks and AI workflows) has a vulnerability where it processes AWS SNS (Simple Notification Service, a messaging system) unsubscribe messages without fully validating them. An authenticated user can modify a URL field in these messages to trick the server into making requests to internal systems, potentially exposing sensitive data like IAM credentials (authentication tokens that control AWS access) or internal services.","solution":"This issue is fixed in version 0.91.1.","labels":["security"],"sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-61681","publishedAt":"2026-09-21T16:17:09.823Z","cveId":"CVE-2026-61681","cweIds":["CWE-918"],"cvssScore":"4.1","cvssSeverity":"medium","severity":"medium","attackType":["supply_chain"],"issueType":"vulnerability","affectedPackages":null,"affectedVendors":["LangChain"],"affectedVendorsRaw":["Hatchet"],"classifierModel":"claude-haiku-4-5-20251001","classifierPromptVersion":"v3","cvssVector":"CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:L/I:N/A:N","attackVector":"network","attackComplexity":"low","privilegesRequired":"high","userInteraction":"none","exploitMaturity":"unknown","epssScore":0,"patchAvailable":null,"disclosureDate":"2026-09-21T16:17:09.823Z","capecIds":["CAPEC-664"],"crossRefCount":0,"attackSophistication":"moderate","impactType":["confidentiality","integrity"],"aiComponentTargeted":"agent","llmSpecific":false,"classifierConfidence":0.85,"researchCategory":null,"atlasIds":["AML.T0010"]}}