Sanaan Fayaz Wani

CVE-2026-63342

Cross-Tenant Durable Task Event Log Disclosure via Missing Authorization Check

—

GHSA-g26x-m427-f48f

Published, fixed and credited. Root cause, the vulnerable code, reproduction and the fix, as published in the advisory itself.

   
Advisory GHSA-g26x-m427-f48f
CVE CVE-2026-63342
Severity Medium (6.3)
CVSS vector CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:N/A:N
CWE CWE-863 (Incorrect Authorization)
Published 2026-06-30

Affected versions

Package Ecosystem Vulnerable Fixed in
github.com/hatchet-dev/hatchet go <= 0.86.29 n/a

Summary

The GET /api/v1/stable/durable-tasks/{durable-task} endpoint (listDurableEventLog) is missing tenant authorization validation, allowing any authenticated user to read durable task event logs from any tenant.

Impact

This CVE requires the attacker to successfully guess the target UUID. Any authenticated Hatchet user can read durable task event logs from any other tenant, exposing:

  • Task display names and workflow identifiers
  • User messages (may contain sensitive business data)
  • Wait conditions and branching logic
  • Timing information

About this writeup

Sanaan Fayaz Wani (GitHub sfwani) reported this vulnerability to the hatchet maintainers under coordinated disclosure and is credited as a reporter in GHSA-g26x-m427-f48f, published 2026-06-30.

All published findings: advisory index.