• Sources: GitHub advisory GHSA-2cp2-2r3c-7p7r, Hydra 1.3.4 release
  • Summary: Hydra's instantiation path resolves the _target_ key of a configuration to a callable and invokes it, so an attacker-controlled configuration becomes code execution when the application passes it to hydra.utils.instantiate(). Loading the configuration alone does not trigger it, and the advisory states that Hydra is not a network service and that exploitation requires a consuming application, library or user workflow to pass attacker-controlled config, CLI overrides or model metadata to that call. The advisory gives the affected range as hydra-core 1.3.3 and earlier, patched in 1.3.4. The 1.3.4 fix is a blacklist, and the advisory states explicitly that it is defense in depth rather than a complete boundary.
  • Why it matters: The advisory states the 1.3.4 blacklist is defense in depth and not a complete boundary, so upgrading is not the whole fix and the calling application still has to validate _target_ against a trusted allowlist.
  • Follow-up: Track whether an allowlist-based instantiation model ships in a later Hydra release.

send feedback on this story