CVE-2026-54746Medium· 6.4▾ SunlitHatchet is a platform for orchestrating background tasks, AI agents, and durable workflows at scale. From 0.40.0 until 0.91.1, the Dispatcher gRPC service does not verify that a request's worker ID belongs to the tenant identified by the…
▾ Sunlit zone — Low / medium · no exploitation signal
impact 35.2 · likelihood 0.1 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Exploit-prediction probability, daily snapshots since Aug 29.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via NVD
0.3%
Last analysed / modified upstream
Hatchet is a platform for orchestrating background tasks, AI agents, and durable workflows at scale. From 0.40.0 until 0.91.1, the Dispatcher gRPC service does not verify that a request's worker ID belongs to the tenant identified by the bearer-token context in Dispatcher/UpsertWorkerLabels and Dispatcher/Unsubscribe. An authenticated owner of any tenant who guesses another tenant's worker UUID can overwrite that worker's affinity labels or disconnect the worker from the dispatcher. This can cause cross-tenant integrity impact and denial of service on multi-tenant Hatchet Cloud or shared self-hosted deployments. Single-tenant deployments are not practically affected because the attacker and target tenant are the same. This issue is fixed in version 0.91.1.
Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
Affected packages:
github.com/hatchet-dev/hatchet >= 0.40.0, < 0.91.2Patched in:
github.com/hatchet-dev/hatchet 0.91.2Connected by shared product, vendor, weakness, or advisory.
CVE-2026-84298Low· 3.1Hatchet is a platform for orchestrating background tasks, AI agents, and durable workflows at scale
CVE-2026-88978Medium· 4.3Hatchet is a platform for orchestrating background tasks, AI agents, and durable workflows at scale
CVE-2026-54322High· 7.7Daytona: Cross-org IDOR in organization role update/delete — any org owner can rewrite or destroy another org's roles
CVE-2026-52799High· 7.5Gogs Missing Authorization in Attachment Download
CVE-2026-52812HighGogs: LFS dedupe path leaks private repo content across tenants
CVE-2026-49258High· 8.8Nebula Mesh: Web UI lacks ownership checks, enabling cross-operator access to hosts and networks (read, block, delete)