THREAT OPS › Threat News › [GHSA] GHSA-2cp2-2r3c-7p7r (high) — Hydra: hydra.utils.instantiate with untrusted config can lead to code execution
[GHSA] GHSA-2cp2-2r3c-7p7r (high) — Hydra: hydra.utils.instantiate with untrusted config can lead to code execution
GHSA-2cp2-2r3c-7p7r Severity: high CVE: CVE-2026-68508
Hydra: hydra.utils.instantiate with untrusted config can lead to code execution
## Summary
`hydra.utils.instantiate()` resolves and calls Python objects from config. If an application passes untrusted config to `instantiate()`, an attacker who controls `_target_` and its arguments can cause arbitrary code execution in the consuming process.
MITRE ATT&CK techniques
Indicators of compromise
- CVE-2026-68508cve
Original source: https://github.com/advisories/GHSA-2cp2-2r3c-7p7r