{"id":"GHSA-phg3-3g28-wq9v","summary":"Hatchet - Unauthenticated OAuth state CSRF / login-CSRF via empty-state collision in ValidateOAuthState","details":"### Summary\n\nHatchet version v0.86.26 and below is vulnerable to OAuth state CSRF (login CSRF / account fixation). \n\nThe vulnerable code clears the session `oauth_state_\u003cintegration\u003e` value to the empty string `\"\"` after a successful OAuth callback rather than removing the key, and the subsequent state-equality check then accepts an empty `?state=` parameter on any later callback request — allowing an unauthenticated attacker to bind an already-authenticated victim's session cookie to an attacker-controlled OAuth identity (account takeover via login-CSRF). \n\n\n### Impact\n\nAffected configurations: any deployment that has enabled at least one of `auth.google.enabled`, `auth.github.enabled`, or the Slack integration, and where the victim has completed at least one OAuth flow on that integration in the current session. Bug present on `main` HEAD and in every tagged release up to and including v0.86.26 (commit `243f41d9e1161e70d47dfc0a6509f1c4ddfc9c23`).","aliases":["CVE-2026-61687","GO-2026-6535"],"modified":"2026-09-28T17:11:11.519741965Z","published":"2026-09-21T15:47:01Z","database_specific":{"nvd_published_at":null,"cwe_ids":["CWE-1275","CWE-287","CWE-352","CWE-384"],"severity":"HIGH","github_reviewed":true,"github_reviewed_at":"2026-09-21T15:47:01Z"},"references":[{"type":"WEB","url":"https://github.com/hatchet-dev/hatchet/security/advisories/GHSA-phg3-3g28-wq9v"},{"type":"WEB","url":"https://github.com/hatchet-dev/hatchet/commit/f90464189ad642251e09412d0f99fde353036428"},{"type":"PACKAGE","url":"https://github.com/hatchet-dev/hatchet"}],"affected":[{"package":{"name":"hatchet","ecosystem":"Go","purl":"pkg:golang/hatchet"},"ranges":[{"type":"SEMVER","events":[{"introduced":"0"},{"fixed":"0.91.1"}]}],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/09/GHSA-phg3-3g28-wq9v/GHSA-phg3-3g28-wq9v.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:H/A:N"}]}