Code Execution Vulnerability in Hydra Framework by Hydra Ecosystem
CVE-2026-68508
7.8HIGH
What is CVE-2026-68508?
The Hydra Framework, prior to version 1.3.4, contains a vulnerability in the hydra.utils.instantiate() function, which allows attacker-controlled inputs to call unsafe operations via the _resolve_target() method. This flaw lets untrusted configuration inputs to execute arbitrary code within the application's environment, posing a severe risk to sensitive data and operations. Users are urged to upgrade to version 1.3.4, which includes the implementation of a target blocking mechanism that enhances security by ensuring only explicitly allowed callables can be executed.
Affected Version(s)
hydra < 1.3.4
