{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/cpes/cpe2.3ahatchethatchet/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":["cpe:2.3:a:hatchet:hatchet:*:*:*:*:*:*:*:*"],"_cs_cves":[{"cvss":7.1,"id":"CVE-2026-61687"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["Hatchet (\u003c 0.91.1)"],"_cs_severities":["high"],"_cs_tags":[],"_cs_type":"advisory","_cs_vendors":["Hatchet"],"content_html":"\u003cp\u003eHatchet versions v0.86.26 and earlier are susceptible to an OAuth state CSRF vulnerability, tracked as CVE-2026-61687. The issue resides in the \u003ccode\u003eValidateOAuthState\u003c/code\u003e function, which handles the verification of the \u003ccode\u003estate\u003c/code\u003e parameter during OAuth callbacks. When an OAuth flow completes successfully, the application incorrectly clears the session-specific \u003ccode\u003eoauth_state_\u0026lt;integration\u0026gt;\u003c/code\u003e key by setting it to an empty string instead of removing the key from the session store.\u003c/p\u003e\n\u003cp\u003eBecause of this logic, subsequent requests containing an empty \u003ccode\u003estate\u003c/code\u003e parameter are incorrectly validated against the existing empty string value in the session. An attacker can exploit this to bind an already-authenticated victim's session cookie to an attacker-controlled OAuth identity. This leads to account fixation or full account takeover, depending on the application context. The vulnerability affects deployments utilizing Google, GitHub, or Slack integrations.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eThe vulnerability allows an unauthenticated attacker to perform account takeover or session fixation against users who have previously performed an OAuth flow within their session. This affects any Hatchet deployment where OAuth integrations are enabled. Successful exploitation requires the victim to have an active session and the attacker to induce the victim to perform an action that triggers the flawed callback logic.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eUpgrade all Hatchet deployments to version 0.91.1 or later to implement proper session state key removal.\u003c/li\u003e\n\u003cli\u003eAudit application logs for abnormal OAuth callback patterns, specifically requests where the \u003ccode\u003estate\u003c/code\u003e parameter is absent or empty in conjunction with successful authentication events.\u003c/li\u003e\n\u003cli\u003eRestrict OAuth callback endpoints to trusted domains and ensure that the \u003ccode\u003estate\u003c/code\u003e parameter is strictly validated for non-empty, cryptographically strong values.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-09-21T19:51:41Z","date_published":"2026-09-21T19:51:41Z","id":"https://feed.craftedsignal.io/briefs/2026-09-hatchet-oauth-csrf/","summary":"Hatchet versions before 0.91.1 contain an OAuth state CSRF vulnerability that allows unauthenticated attackers to hijack sessions by exploiting improper session state clearing during callback processing.","title":"OAuth State CSRF Vulnerability in Hatchet","url":"https://feed.craftedsignal.io/briefs/2026-09-hatchet-oauth-csrf/"}],"language":"en","title":"CraftedSignal Threat Feed - Cpe:2.3:a:hatchet:hatchet:*:*:*:*:*:*:*:*","version":"https://jsonfeed.org/version/1.1"}