BBUGFLARE

Public library

Cybersecurity articles

Automated coverage from researcher feeds — text + code extraction, no thumbnails. Sort by recent, popular, or trending.

GitHub Advisories35
Hydra: hydra.utils.instantiate with untrusted config can lead to code execution

## Summary `hydra.utils.instantiate()` resolves and calls Python objects from config. If an application passes untrusted config to `instantiate()`, an attacker who controls `_target_` and its arguments can cause arbitrary code execution in the consuming process. Hydra is not a network service. Ex...

Read →

Prefer original Bugflare research? Browse writeups