CVE-2026-88978: Hatchet is a platform for orchestrating background tasks, AI agents, and durable workflows at scale. Prior to 0.106.1, t
Summary
Hatchet is a platform for managing background tasks and AI workflows at scale. Before version 0.106.1, a security flaw in the WorkerStatus gRPC polling path (a communication method between processes) allowed an authenticated user from one tenant (a separate customer account) to access another tenant's task records if they knew the task's unique identifier, though this was difficult because identifiers use UUIDv4 (a specific random ID format that's hard to guess).
Solution / Mitigation
This issue is fixed in version 0.106.1.
Vulnerability Details
4.3(medium)
EPSS: 0.0%
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
network
low
low
none
September 21, 2026
Classification
Affected Vendors
Related Issues
CVE-2026-63086: text-generation-inference through 3.3.7 contains a server-side request forgery (SSRF) vulnerability in the OpenAI-compat
CVE-2024-37052: Deserialization of untrusted data can occur in versions of the MLflow platform running version 1.1.0 or newer, enabling
Original source: https://nvd.nist.gov/vuln/detail/CVE-2026-88978
First tracked: September 21, 2026 at 02:08 PM
Classified by LLM (prompt v3) · confidence: 85%