CVE-2026-61687: Hatchet is a platform for orchestrating background tasks, AI agents, and durable workflows at scale. Prior to 0.91.1, Va
Summary
Hatchet is a platform for running background tasks and AI workflows. Before version 0.91.1, it had a security flaw where the OAuth state validation (a security check that confirms login requests are legitimate) could be bypassed by an attacker, allowing them to connect a victim's account to an attacker's login credentials if certain OAuth providers like Google or GitHub were enabled.
Solution / Mitigation
This issue is fixed in version 0.91.1.
Vulnerability Details
7.1(high)
EPSS: 0.0%
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:H/A:N
network
low
none
required
September 21, 2026
Classification
Affected Vendors
Related Issues
CVE-2026-34371: LibreChat is a ChatGPT clone with additional features. Prior to 0.8.4, LibreChat trusts the name field returned by the e
CVE-2024-27444: langchain_experimental (aka LangChain Experimental) in LangChain before 0.1.8 allows an attacker to bypass the CVE-2023-
Original source: https://nvd.nist.gov/vuln/detail/CVE-2026-61687
First tracked: September 21, 2026 at 02:08 PM
Classified by LLM (prompt v3) · confidence: 85%