Remote Code Execution Vulnerability in Hydra Framework by Hydra Ecosystem
CVE-2026-106440

7.8HIGH

Key Information:

Status
Vendor
CVE Published:
6 October 2026

What is CVE-2026-106440?

The hydra-optuna-sweeper package within the Hydra framework is exposed to a remote code execution vulnerability. Versions 1.2.0 to 1.3.0 and the development version 1.4.0.dev10 are affected due to improper handling of a user-controlled dotted path which is executed without sufficient security checks. An attacker managing the Optuna sweep configuration can leverage this flaw to execute arbitrary Python code, potentially circumventing security measures designed to restrict execution to trusted sources. The vulnerability has been addressed in versions 1.3.0 and 1.4.0.dev10.

Affected Version(s)

hydra >= 1.2.0, < 1.3.0 < 1.2.0, 1.3.0

hydra >= 1.4.0.dev4, < 1.4.0.dev10 < 1.4.0.dev4, 1.4.0.dev10

References

CVSS V3.1

Score:
7.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.