hydra-core is vulnerable to Code Injection
78
High Risk
Hydra's hydra.utils.instantiate() resolves and calls Python objects named by the _target_ string in a configuration node. When a consuming application passes untrusted configuration into this function, it can lead to arbitrary code execution, allowing reading or modifying files, credentials, and application state. The fix adds a default blocklist of high-risk callables and modules and permits an explicit allowlist override.
You are affected if you are using a version that falls within the vulnerable range and your application passes untrusted config to hydra.utils.instantiate().
hydra-core is vulnerable to Code Injection in versions 0.0.1 - 1.3.3.
Upgrade the hydra-core library to the patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant