CVE-2026-68508 | Facebook Research Hydra up to 1.3.3 Instantiate _instantiate2.py hydra.utils.instantiate code injection
A vulnerability classified as problematic was found in Facebook Research Hydra up to 1.3.3. This affects the function hydra.utils.instantiate of the file hydra/_internal/instantiate/_instantiate2.py of the component Instantiate. Executing a manipulation can lead to code injection.
This vulnerability appears as CVE-2026-68508. The attack requires local access. There is no available exploit.
Upgrading the affected component is advised.VulDB Recent EntriesRead More