Arbitrary Code Execution in hydra-optuna-sweeper
The hydra-optuna-sweeper package allows arbitrary code execution by resolving and invoking untrusted callables provided through the custom_search_space configuration parameter.
CVE search metadata
CVE search record: CVE-2026-106440. Severity: high. CVSS: 7.8. KEV: no. Product: hydra-optuna-sweeper (>= 1.2.0, < 1.3.0), hydra-optuna-sweeper (>= 1.4.0.dev4, < 1.4.0.dev10). Brief: Arbitrary Code Execution in hydra-optuna-sweeper. Brief link: https://feed.craftedsignal.io/briefs/2026-10-hydra-rce/
The hydra-optuna-sweeper package contains a vulnerability (CVE-2026-106440) that permits arbitrary code execution. The vulnerability originates in the handling of the hydra.sweeper.custom_search_space configuration parameter. The component incorrectly used the low-level hydra.utils.get_method() API to resolve and execute callables specified in the configuration. Because get_method() is designed for trusted input, it lacks the safety checks, execution policies, and whitelists enforced by higher-level APIs like instantiate().
An attacker who can control an application's Optuna configuration or provide command-line overrides can specify a dotted path to any importable Python callable. The application then resolves and executes this code with the full privileges of the host process. This vulnerability affects stable versions from 1.2.0 up to 1.3.0, and development releases from 1.4.0.dev4 to 1.4.0.dev9. The issue was addressed by moving configuration-driven construction to the instantiate() helper, which respects security boundaries.
Attack Chain
- Attacker gains the ability to influence Hydra application configuration via file modification or command-line overrides.
- Attacker crafts a malicious
hydra.sweeper.custom_search_spaceparameter containing the path to a sensitive importable Python callable. - The Hydra application process loads the configuration during the Optuna sweep initialization.
- The
hydra-optuna-sweepercomponent receives the untrusted path from the configuration. - The component passes this path directly to
hydra.utils.get_method(). - The
get_method()API resolves the string path into a callable object in the application memory space. - The application invokes the resolved callable, resulting in arbitrary code execution within the context of the application.
Impact
Successful exploitation results in arbitrary code execution with the privileges of the application process. This allows for full system compromise if the Hydra controller process runs with elevated permissions. The impact is significant for environments where Optuna sweep configurations are generated based on user-supplied parameters or pulled from external sources.
Recommendation
- Upgrade
hydra-optuna-sweeperto version 1.3.0 or later for stable releases, or 1.4.0.dev10 or later for development releases, to resolve CVE-2026-106440. - Ensure that Optuna sweep configuration files and command-line arguments are treated as trusted inputs and are not modifiable by unauthorized users.
- Implement strict access controls on the application environment to prevent untrusted modules or packages from being placed on the Python import path.
Immediate actions
Upgrade hydra-optuna-sweeper to version 1.3.0 or 1.4.0.dev10 to mitigate CVE-2026-106440
Mitigations
Restrict write access to configuration files and command-line overrides used by Hydra applications
CVE-2026-106440