Impact
Hatchet’s REST API provided a GET endpoint for durable task event logs that did not enforce the target tenant as a resource parent. An authenticated user who could obtain another tenant’s durable task UUID could therefore read the entire event log of that task. The disclosed data includes task display names, workflow identifiers, user messages, wait conditions, branching logic, and timing information, giving an attacker insight into another tenant’s internal workflow structure. The vulnerability does not affect integrity or availability, but it may be leveraged to inform further attacks or for operational reconnaissance.
Affected Systems
Any installation of the Hatchet platform from hatchet-dev prior to version 0.91.1, where the API endpoint /api/v1/stable/durable-tasks/{durable-task} is exposed, is affected. No specific CPE strings are listed, but the problem is confined to that product and those versions.
Risk and Exploitability
The CVSS score of 6.3 indicates moderate severity, and the EPSS score is not available. Because the attack vector requires legitimate authentication but cross‐tenant lack of authorization, the likelihood of exploitation depends on an attacker’s ability to locate or guess a target tenant’s durable task UUID. The lack of display in the KEV catalog suggests no publicly available exploits at this time, but the information disclosure may still pose significant risk to tenant confidentiality.
OpenCVE Enrichment