CVE-2026-61687 with a CVSS score of 7.1 is a vulnerability in Hatchet version v0.86.26 and below that allows OAuth state CSRF, or login-CSRF via empty-state collision in ValidateOAuthState, enabling an unauthenticated attacker to bind an already-authenticated victim's session cookie to an attacker-controlled OAuth identity, resulting in account takeover due to the vulnerable code clearing the session oauth_state_<integration> value to the empty string after a successful OAuth callback rather than removing the key, and subsequently accepting an empty ?state= parameter on any later callback request, affecting configurations where at least one of auth.google.enabled, auth.github.enabled, or the Slack integration is enabled, and the victim has completed at least one OAuth flow on that integration in the current session, with affected versions including hatchet < 0.91.1.
We recommend you to update Hatchet to version 0.91.1.[/subscribe_to_unlock_form]
CVE-2026-61687 with a CVSS score of 7.1 is a vulnerability in Hatchet version v0.86.26 and below that allows OAuth state CSRF, or login-CSRF via empty-state collision in ValidateOAuthState, enabling an unauthenticated attacker to bind an already-authenticated victim's session cookie to an attacker-controlled OAuth identity, resulting in account takeover due to the vulnerable code clearing the session oauth_state_<integration> value to the empty string after a successful OAuth callback rather than removing the key, and subsequently accepting an empty ?state= parameter on any later callback request, affecting configurations where at least one of auth.google.enabled, auth.github.enabled, or the Slack integration is enabled, and the victim has completed at least one OAuth flow on that integration in the current session, with affected versions including hatchet < 0.91.1.
We recommend you to update Hatchet to version 0.91.1.[emaillocker id="1283"]
The following reports contain further technical details:
[/emaillocker]