Tag
Hydra-core versions prior to 1.3.6 and 1.4.0.dev9 are vulnerable to arbitrary code execution due to improper validation of logging configuration passed to dictConfig, allowing attackers to invoke arbitrary Python callables.