GHSA-9q4h-f4x5-ffq8
Hatchet: Cross-tenant durable callback payload disclosure in Hatchet V1 Dispatcher
Quick fix
GHSA-9q4h-f4x5-ffq8 — github.com/hatchet-dev/hatchet: upgrade to the fixed version with the command below.
go get github.com/hatchet-dev/hatchet@v0.95.3Details
## Summary
The V1 `DurableTask` stream handler registers worker-supplied durable task external IDs in an in-memory callback routing map before verifying that the authenticated tenant owns the task. If the tenant-scoped ownership check fails, the handler logs the error and continues, but the map entry persists until the stream closes.
Durable callback delivery resolves the destination stream by `task_external_id` only, without checking tenant identity. As a result, a tenant A worker that knows a tenant B durable task external UUID can hold its stream open and receive tenant B's durable callback result payload when the callback is delivered on the same dispatcher process.
## Impact
This advisory requires an attacker to successfully guess a durable task external UUID belonging to another tenant. Durable task external IDs are generated with `uuid.New()` (UUIDv4) and are not enumerable across tenants, so exploitation requires prior knowledge of a target task UUID through an out-of-band channel. Thus, while the following environments are impacted, there is an extremely low probability it would be exploited.
**Who is impacted.** Any Hatchet deployment that hosts more than one tenant on the same instance: - Hatchet Cloud (multi-tenant SaaS) - Self-hosted Hatchet with multiple internal teams / business units sharing one instance - Any deployment where a single tenant's API token can be obtained by an attacker
Single-tenant self-hosted deployments are unaffected in practice (the "victim" and "attacker" tenants would be the same).
Are you affected?
Enter the version of the package you're using.
Affected packages
0Fixed in: 0.95.3go get github.com/hatchet-dev/hatchet@v0.95.3