Fetching from the wire…
Security2026-08-29 · source-backed
CVE-2026-54746 (6.4) affects Hatchet from 0.40.0 until 0.91.1: the Dispatcher gRPC service didn't verify that a request's worker ID belonged to the tenant in the bearer-token context, in UpsertWorkerLabels and related calls. Hatchet orchestrates background tasks, AI agents and durable workflows, so this is a cross-tenant boundary failure in shared agent infrastructure rather than in a single-user dev tool. 0.91.1 fixes it. (NVD)
Each link below shares sources, entities, or timing with this story.
Shared entities / Same source domain / Shared topic / Earlier coverage / Tension
Both cover CVE, NVD; reported by the same outlet (nvd.nist.gov); overlapping topics (boundary, call).
Shared entities / Same source domain / Shared topic / Earlier coverage
Both cover CVE, NVD; reported by the same outlet (nvd.nist.gov); overlapping topics (agent, boundary).
Both cover CVE, NVD; reported by the same outlet (nvd.nist.gov); overlapping topics (agent, context).
Both cover CVE, NVD; reported by the same outlet (nvd.nist.gov); overlapping topics (agent, context).
Shared entities / Same source domain / Earlier coverage / Tension
Both cover CVE, NVD; reported by the same outlet (nvd.nist.gov); earlier CVE coverage from 2026-08-27.
Both cover CVE, NVD; reported by the same outlet (nvd.nist.gov); earlier CVE coverage from 2026-08-26.
Shared entities / Same source domain / Earlier coverage
Both cover CVE, NVD; reported by the same outlet (nvd.nist.gov); earlier CVE coverage from 2026-08-28.
Both cover CVE, NVD; reported by the same outlet (nvd.nist.gov); earlier CVE coverage from 2026-08-28.