PT-2026-79449 · Pypi · Hydra

CVE-2026-68508

·

Published

2026-08-21

·

Updated

2026-09-10

CVSS v3.1

7.8

High

VectorAV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Hydra versions prior to 1.3.4
Description The hydra.utils.instantiate() function resolves and calls Python objects selected by configuration through the resolve target() function in hydra/ internal/instantiate/ instantiate2.py. This allows attacker-controlled target values and arguments to select dangerous callables. Applications, libraries, CLI workflows, or model loaders that pass untrusted configuration, CLI overrides, or model metadata into hydra.utils.instantiate() may allow the execution of arbitrary code within the process, which could lead to the reading or modification of files and credentials, or the termination of the process.
Recommendations Update to version 1.3.4.

Exploit

Fix

Code Injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-68508
GHSA-2CP2-2R3C-7P7R
PYSEC-2026-3850

Affected Products

Hydra