
Hatchet OAuth state CSRF / login-CSRF. CVE-2026-61687: empty-state collision in ValidateOAuthState enables unauthenticated OAuth state CSRF. Another auth-boundary issue in a workflow/orchestration-style service. Worth a look if the product is in your stack. https://vulnso.com/vuln/hatchet-unauthenticated-oauth-state-csrf-login-csrf-via-empty-state-collision-in-validateoauthstate #Cybersecurity #AI #AISecurity #MCP #Claude #GPT #Infosec #Trending #AppSec #AuthBypass

