Impact
Hatchet, a platform for orchestrating background tasks and durable workflows, has a flaw where a V1 Dispatcher operation stores a worker’s supplied task_external_id in a routing map before verifying tenant ownership, and later resolves callback delivery by task UUID without tenant context. This allows an authenticated worker from one tenant to open a stream on the same dispatcher process and receive the durable callback result payload of a task belonging to another tenant. The vulnerability leads to the exposure of potentially sensitive data across tenant boundaries, compromising confidentiality. The weakness is classified by CWE-639 (Information Exposure Through Incomplete Authentication) and CWE-862 (Missing Authorization).
Affected Systems
The Hatchet platform, specifically the hatchet-dev Hatchet product, is affected in all releases prior to version 0.95.3. Users of earlier releases that rely on the V1 Dispatcher for durable tasks may be susceptible to this cross‑tenant disclosure. Single‑tenant deployments are not practically impacted because the issue requires multiple tenants sharing the same dispatcher.
Risk and Exploitability
The CVSS score for this vulnerability is 3.1, reflecting a low severity primarily due to its limited exploitation scope and the need for an authenticated worker with a shared dispatcher process. EPSS information is not available, so a precise exploitation probability cannot be quoted. The vulnerability is not listed in CISA’s KEV catalog, indicating no known widespread exploitation. The likely attack vector requires an attacker to authenticate as a legitimate worker, identify another tenant’s durable task UUID, and maintain an open stream on the shared dispatcher. Given these prerequisites, the risk, while real, is constrained to environments where multiple tenants share dispatcher resources.
OpenCVE Enrichment
Github GHSA