Unauthenticated OAuth State CSRF Vulnerability in Hatchet
Hatchet versions v0.86.26 and below are vulnerable to an unauthenticated OAuth state CSRF (login CSRF / account fixation) attack. This vulnerability allows an attacker to bind an already-authenticated victim's session cookie to an attacker-controlled OAuth identity, potentially leading to account takeover. The vulnerability has a CVSS score of 7.1.