CVE-2026-61681: Hatchet is a platform for orchestrating background tasks, AI agents, and durable workflows at scale. Prior to 0.91.1, th
Summary
Hatchet (a platform for running background tasks and AI workflows) has a vulnerability where it processes AWS SNS (Simple Notification Service, a messaging system) unsubscribe messages without fully validating them. An authenticated user can modify a URL field in these messages to trick the server into making requests to internal systems, potentially exposing sensitive data like IAM credentials (authentication tokens that control AWS access) or internal services.
Solution / Mitigation
This issue is fixed in version 0.91.1.
Vulnerability Details
4.1(medium)
EPSS: 0.0%
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:L/I:N/A:N
network
low
high
none
September 21, 2026
Classification
Taxonomy References
Affected Vendors
Related Issues
CVE-2026-63086: text-generation-inference through 3.3.7 contains a server-side request forgery (SSRF) vulnerability in the OpenAI-compat
CVE-2026-34371: LibreChat is a ChatGPT clone with additional features. Prior to 0.8.4, LibreChat trusts the name field returned by the e
Original source: https://nvd.nist.gov/vuln/detail/CVE-2026-61681
First tracked: September 21, 2026 at 02:08 PM
Classified by LLM (prompt v3) · confidence: 85%