Disclosure summary
## Summary `hydra-optuna-sweeper` accepted a configuration-controlled dotted path in `hydra.sweeper.custom_search_space`, resolved it with the lower-level `hydra.utils.get_method()` API, and later invoked the returned callable. Hydra's object-lookup helpers intentionally trust their input and do not apply the execution policy used by `instantiate()` and logging configuration. As a result, untrusted Optuna multirun configuration could select installed Python code for execution in the Hydra controller process. ## Impact Exploitation requires control of an application's Optuna sweep configuration or command-line overrides and an importable callable in the application's environment. Selected code runs with the privileges of the application. On affected Hydra 1.4 development releases, this path bypasses an execution whitelist provided by trusted application code. Hydra 1.3 has no execution-whitelist security boundary; there, the same change restores the legacy blocklist as defense in depth. ## Fix The Optuna sweeper now resolves the configured callback through `hydra.utils.instantiate()` as a partial callable. On Hydra 1.4, the active execution whitelist therefore authorizes the callbac
Source-specific records & product guidance
Sources retain their own attribution and scoring. Follow the original record to confirm affected versions, fixed releases, and configuration conditions.
GitHub Reviewed Security Advisories · GHSA-5jjj-9xc3-rm56
Open original source · Updated Oct 07, 2026
Hydra: Optuna custom_search_space can resolve and execute untrusted callables via get_method
Source severity: HIGH / 0
| Ecosystem | Package | Affected range | First patched |
|---|---|---|---|
| pip | hydra-optuna-sweeper | >= 1.2.0, < 1.3.0 | 1.3.0 |
| pip | hydra-optuna-sweeper | >= 1.4.0.dev4, < 1.4.0.dev10 | 1.4.0.dev10 |
Original records & references
- NIST NVD record
- CVE Program record
- github.com — Reviewed advisory
PUBLISHED 2026-10-07T16:24:02-04:00
MODIFIED 2026-10-07T16:24:04-04:00
INGESTED 2026-10-08T12:30:39-04:00