Vendor
Hatchet versions before 0.91.1 contain an OAuth state CSRF vulnerability that allows unauthenticated attackers to hijack sessions by exploiting improper session state clearing during callback processing.