{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/products/hydra-optuna-sweeper--1.4.0.dev4--1.4.0.dev10/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":["cpe:2.3:a:hydra:hydra-optuna-sweeper:*:*:*:*:*:*:*:*"],"_cs_cves":[{"cvss":7.8,"id":"CVE-2026-106440"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["hydra-optuna-sweeper (\u003e= 1.2.0, \u003c 1.3.0)","hydra-optuna-sweeper (\u003e= 1.4.0.dev4, \u003c 1.4.0.dev10)"],"_cs_severities":["high"],"_cs_tags":["arbitrary-code-execution","hydra","supply-chain"],"_cs_type":"advisory","_cs_vendors":["Hydra"],"content_html":"\u003cp\u003eThe \u003ccode\u003ehydra-optuna-sweeper\u003c/code\u003e package contains a vulnerability (CVE-2026-106440) that permits arbitrary code execution. The vulnerability originates in the handling of the \u003ccode\u003ehydra.sweeper.custom_search_space\u003c/code\u003e configuration parameter. The component incorrectly used the low-level \u003ccode\u003ehydra.utils.get_method()\u003c/code\u003e API to resolve and execute callables specified in the configuration. Because \u003ccode\u003eget_method()\u003c/code\u003e is designed for trusted input, it lacks the safety checks, execution policies, and whitelists enforced by higher-level APIs like \u003ccode\u003einstantiate()\u003c/code\u003e.\u003c/p\u003e\n\u003cp\u003eAn attacker who can control an application's Optuna configuration or provide command-line overrides can specify a dotted path to any importable Python callable. The application then resolves and executes this code with the full privileges of the host process. This vulnerability affects stable versions from 1.2.0 up to 1.3.0, and development releases from 1.4.0.dev4 to 1.4.0.dev9. The issue was addressed by moving configuration-driven construction to the \u003ccode\u003einstantiate()\u003c/code\u003e helper, which respects security boundaries.\u003c/p\u003e\n\u003ch2 id=\"attack-chain\"\u003eAttack Chain\u003c/h2\u003e\n\u003col\u003e\n\u003cli\u003eAttacker gains the ability to influence Hydra application configuration via file modification or command-line overrides.\u003c/li\u003e\n\u003cli\u003eAttacker crafts a malicious \u003ccode\u003ehydra.sweeper.custom_search_space\u003c/code\u003e parameter containing the path to a sensitive importable Python callable.\u003c/li\u003e\n\u003cli\u003eThe Hydra application process loads the configuration during the Optuna sweep initialization.\u003c/li\u003e\n\u003cli\u003eThe \u003ccode\u003ehydra-optuna-sweeper\u003c/code\u003e component receives the untrusted path from the configuration.\u003c/li\u003e\n\u003cli\u003eThe component passes this path directly to \u003ccode\u003ehydra.utils.get_method()\u003c/code\u003e.\u003c/li\u003e\n\u003cli\u003eThe \u003ccode\u003eget_method()\u003c/code\u003e API resolves the string path into a callable object in the application memory space.\u003c/li\u003e\n\u003cli\u003eThe application invokes the resolved callable, resulting in arbitrary code execution within the context of the application.\u003c/li\u003e\n\u003c/ol\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation results in arbitrary code execution with the privileges of the application process. This allows for full system compromise if the Hydra controller process runs with elevated permissions. The impact is significant for environments where Optuna sweep configurations are generated based on user-supplied parameters or pulled from external sources.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eUpgrade \u003ccode\u003ehydra-optuna-sweeper\u003c/code\u003e to version 1.3.0 or later for stable releases, or 1.4.0.dev10 or later for development releases, to resolve CVE-2026-106440.\u003c/li\u003e\n\u003cli\u003eEnsure that Optuna sweep configuration files and command-line arguments are treated as trusted inputs and are not modifiable by unauthorized users.\u003c/li\u003e\n\u003cli\u003eImplement strict access controls on the application environment to prevent untrusted modules or packages from being placed on the Python import path.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-10-07T22:53:02Z","date_published":"2026-10-07T22:53:02Z","id":"https://feed.craftedsignal.io/briefs/2026-10-hydra-rce/","summary":"The hydra-optuna-sweeper package allows arbitrary code execution by resolving and invoking untrusted callables provided through the custom_search_space configuration parameter.","title":"Arbitrary Code Execution in hydra-optuna-sweeper","url":"https://feed.craftedsignal.io/briefs/2026-10-hydra-rce/"}],"language":"en","title":"CraftedSignal Threat Feed - Hydra-Optuna-Sweeper (\u003e= 1.4.0.dev4, \u003c 1.4.0.dev10)","version":"https://jsonfeed.org/version/1.1"}