HIGH
hydra-ecosystem
CVE published 2026-08-21
CVE-2026-68508
AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-08-21T21:17:02.963Z and has not been modified since then. The Hydra framework versions prior to 1.3.4 are vulnerable to arbitrary code execution due to the insecure use of hydra.utils.instantiate(). This function allows attacker-controlled target values and arguments to choose dangerous callables, enab [truncated]