Remote Code Execution Vulnerability in Hydra Framework by Hydra Ecosystem
CVE-2026-106440
7.8HIGH
What is CVE-2026-106440?
The hydra-optuna-sweeper package within the Hydra framework is exposed to a remote code execution vulnerability. Versions 1.2.0 to 1.3.0 and the development version 1.4.0.dev10 are affected due to improper handling of a user-controlled dotted path which is executed without sufficient security checks. An attacker managing the Optuna sweep configuration can leverage this flaw to execute arbitrary Python code, potentially circumventing security measures designed to restrict execution to trusted sources. The vulnerability has been addressed in versions 1.3.0 and 1.4.0.dev10.
Affected Version(s)
hydra >= 1.2.0, < 1.3.0 < 1.2.0, 1.3.0
hydra >= 1.4.0.dev4, < 1.4.0.dev10 < 1.4.0.dev4, 1.4.0.dev10
