<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:webfeeds="http://webfeeds.org/rss/1.0"><channel><title>Hydra-Optuna-Sweeper (&gt;= 1.4.0.dev4, &lt; 1.4.0.dev10) - CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/products/hydra-optuna-sweeper--1.4.0.dev4--1.4.0.dev10/</link><description>Trending threats, MITRE ATT&amp;CK coverage, and detection metadata. Fed continuously.</description><generator>Hugo</generator><language>en</language><managingEditor>hello@craftedsignal.io</managingEditor><webMaster>hello@craftedsignal.io</webMaster><lastBuildDate>Wed, 07 Oct 2026 22:53:02 +0000</lastBuildDate><atom:link href="https://feed.craftedsignal.io/products/hydra-optuna-sweeper--1.4.0.dev4--1.4.0.dev10/feed.xml" rel="self" type="application/rss+xml"/><image><url>https://feed.craftedsignal.io/favicon-32x32.png</url><title>CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/</link><width>32</width><height>32</height></image><webfeeds:icon>https://feed.craftedsignal.io/favicon.svg</webfeeds:icon><item><title>Arbitrary Code Execution in hydra-optuna-sweeper</title><link>https://feed.craftedsignal.io/briefs/2026-10-hydra-rce/</link><pubDate>Wed, 07 Oct 2026 22:53:02 +0000</pubDate><author>hello@craftedsignal.io</author><guid isPermaLink="true">https://feed.craftedsignal.io/briefs/2026-10-hydra-rce/</guid><description>The hydra-optuna-sweeper package allows arbitrary code execution by resolving and invoking untrusted callables provided through the custom_search_space configuration parameter.</description><content:encoded><![CDATA[<p>The <code>hydra-optuna-sweeper</code> package contains a vulnerability (CVE-2026-106440) that permits arbitrary code execution. The vulnerability originates in the handling of the <code>hydra.sweeper.custom_search_space</code> configuration parameter. The component incorrectly used the low-level <code>hydra.utils.get_method()</code> API to resolve and execute callables specified in the configuration. Because <code>get_method()</code> is designed for trusted input, it lacks the safety checks, execution policies, and whitelists enforced by higher-level APIs like <code>instantiate()</code>.</p>
<p>An attacker who can control an application's Optuna configuration or provide command-line overrides can specify a dotted path to any importable Python callable. The application then resolves and executes this code with the full privileges of the host process. This vulnerability affects stable versions from 1.2.0 up to 1.3.0, and development releases from 1.4.0.dev4 to 1.4.0.dev9. The issue was addressed by moving configuration-driven construction to the <code>instantiate()</code> helper, which respects security boundaries.</p>
<h2 id="attack-chain">Attack Chain</h2>
<ol>
<li>Attacker gains the ability to influence Hydra application configuration via file modification or command-line overrides.</li>
<li>Attacker crafts a malicious <code>hydra.sweeper.custom_search_space</code> parameter containing the path to a sensitive importable Python callable.</li>
<li>The Hydra application process loads the configuration during the Optuna sweep initialization.</li>
<li>The <code>hydra-optuna-sweeper</code> component receives the untrusted path from the configuration.</li>
<li>The component passes this path directly to <code>hydra.utils.get_method()</code>.</li>
<li>The <code>get_method()</code> API resolves the string path into a callable object in the application memory space.</li>
<li>The application invokes the resolved callable, resulting in arbitrary code execution within the context of the application.</li>
</ol>
<h2 id="impact">Impact</h2>
<p>Successful exploitation results in arbitrary code execution with the privileges of the application process. This allows for full system compromise if the Hydra controller process runs with elevated permissions. The impact is significant for environments where Optuna sweep configurations are generated based on user-supplied parameters or pulled from external sources.</p>
<h2 id="recommendation">Recommendation</h2>
<ul>
<li>Upgrade <code>hydra-optuna-sweeper</code> to version 1.3.0 or later for stable releases, or 1.4.0.dev10 or later for development releases, to resolve CVE-2026-106440.</li>
<li>Ensure that Optuna sweep configuration files and command-line arguments are treated as trusted inputs and are not modifiable by unauthorized users.</li>
<li>Implement strict access controls on the application environment to prevent untrusted modules or packages from being placed on the Python import path.</li>
</ul>
]]></content:encoded><category domain="severity">high</category><category domain="type">advisory</category><category>arbitrary-code-execution</category><category>hydra</category><category>supply-chain</category></item></channel></rss>