THREATOPS
THREAT OPSThreat News › [GHSA] GHSA-2cp2-2r3c-7p7r (high) — Hydra: hydra.utils.instantiate with untrusted config can lead to code execution

[GHSA] GHSA-2cp2-2r3c-7p7r (high) — Hydra: hydra.utils.instantiate with untrusted config can lead to code execution

medgithub_advisoriesPublished 2026-08-21

GHSA-2cp2-2r3c-7p7r Severity: high CVE: CVE-2026-68508

Hydra: hydra.utils.instantiate with untrusted config can lead to code execution

## Summary

`hydra.utils.instantiate()` resolves and calls Python objects from config. If an application passes untrusted config to `instantiate()`, an attacker who controls `_target_` and its arguments can cause arbitrary code execution in the consuming process.

MITRE ATT&CK techniques

Indicators of compromise

Original source: https://github.com/advisories/GHSA-2cp2-2r3c-7p7r