Overview
A maximum-severity, CVSS 10.0 code injection vulnerability has been disclosed in InternLM MindSearch, an open-source AI search-agent framework that plans and executes multi-step web research tasks. Tracked as CVE-2026-105135 and classified under CWE-74 (Injection) and CWE-94 (Code Injection), the flaw sits in MindSearch's Planner Agent component and allows a remote, unauthenticated attacker to execute arbitrary code on any server running the affected version.
The vulnerable code path is the ExecutionAction.run function in mindsearch/agent/graph.py, reachable through the framework's POST /solve endpoint. The Planner Agent passes the request's inputs argument into this execution routine without adequately validating or sanitizing it, so an attacker who crafts a malicious inputs payload can inject code that the agent's execution step will run directly on the host.
The vulnerability affects MindSearch 0.1.0, was published on October 4, 2026, and according to reporting on the disclosure, the vendor was contacted ahead of publication but did not respond. No fixed version has been identified as of this writing, and the CVE is not currently listed in CISA's Known Exploited Vulnerabilities (KEV) catalog, though sources differ on whether proof-of-concept exploit code is already circulating.
Technical Details
| Field | Value |
|---|---|
| CVE ID | CVE-2026-105135 |
| CWE | CWE-74 (Injection), CWE-94 (Code Injection) |
| Severity | Critical |
| CVSS 3.1 Score | 10.0 |
| CVSS 3.1 Vector | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H |
| Attack Vector | Network (/solve endpoint) |
| Authentication | None required |
| Privileges Required | None |
| User Interaction | None |
| Affected Software | InternLM MindSearch 0.1.0 |
| Fixed Version | None identified at time of publication — vendor unresponsive |
How It Works
MindSearch's Planner Agent decomposes a user's research query into an execution graph of sub-tasks, then runs each step through ExecutionAction.run in mindsearch/agent/graph.py. That function accepts an inputs argument intended to carry the step's parameters, but the framework does not sufficiently restrict or escape what that argument can contain before it reaches the underlying execution logic.
An unauthenticated attacker who sends a crafted request to POST /solve with a malicious inputs value can have arbitrary code run directly by the Planner Agent — with the full confidentiality, integrity, and availability impact reflected in the CVSS vector's C:H/I:H/A:H rating. No session, API key, or prior interaction is needed; reachability to the endpoint is the only prerequisite.
Why Agentic AI Frameworks Raise the Stakes
MindSearch is designed to autonomously plan and execute multi-step tasks, often with access to search tools, code execution, or other connected services. A code injection bug in the component responsible for actually running those planned steps doesn't just compromise the application — it hands the attacker the same execution capability the agent itself has, which in many deployments includes outbound network access, file system access, and any credentials the agent process holds for its downstream tools.
Impact Assessment
| Impact Area | Description |
|---|---|
| Remote Code Execution | Unauthenticated attacker can execute arbitrary code via the Planner Agent's execution path |
| Credential/Data Exposure | Code execution on the host can expose any API keys or credentials the MindSearch process holds for its connected tools |
| Lateral Movement | A compromised agent host with outbound network access or tool integrations can be used to pivot into other connected systems |
| No Vendor Patch Yet | The vendor did not respond to disclosure, leaving no official fixed version to upgrade to as of publication |
| Low Bar to Exploit | No authentication, privileges, or user interaction required — only network reachability to /solve |
| AI Supply Chain Exposure | Any product or internal tool that embeds MindSearch as a dependency inherits this vulnerability |
Who Is At Risk
Any organization running MindSearch 0.1.0, whether as a standalone deployment or embedded as a dependency inside a larger AI product, is at risk if the /solve endpoint is reachable from an untrusted network. Given the framework's purpose — autonomous research agents that often run with broad tool access — successful exploitation can be a stepping stone into whatever systems the agent itself is permitted to touch.
Mitigation
Immediate Actions
- Take affected MindSearch instances off any untrusted network (including the public internet) until a fix is available; there is currently no patched version to upgrade to.
- Audit MindSearch usage across your environment, including as a transitive dependency in other AI tooling, to confirm whether version 0.1.0 is in use.
- Review logs for unexpected requests to the
/solveendpoint, especially payloads containing unusualinputsvalues or shell/code-like syntax.
For Developers Embedding MindSearch
- Do not expose the Planner Agent's
/solveendpoint directly to untrusted callers; place it behind an authenticated proxy or gateway at minimum until an upstream fix lands. - Run MindSearch inside a sandboxed, least-privilege environment (restricted file system, no credentials beyond what a single task strictly needs) so a code-injection compromise can't reach broader infrastructure.
- Track the upstream project for a patched release, and watch for a response from the maintainers given the current lack of vendor engagement on this disclosure.
For Security Teams
- Add InternLM MindSearch to AI/ML software inventories — treat agentic AI frameworks with execution capabilities as high-value targets requiring the same scrutiny as any other network-facing service.
- Monitor for public proof-of-concept exploit code and for this CVE's addition to CISA's KEV catalog, and prioritize isolation over waiting for KEV listing given the unauthenticated, maximum-severity profile.
- Flag any internal AI agent framework that executes model-planned code paths for a security review of its input-handling boundaries, independent of this specific CVE.
Key Takeaways
- CVE-2026-105135 is a CVSS 10.0 Critical code injection vulnerability in InternLM MindSearch 0.1.0, classified under CWE-74/CWE-94.
- The flaw lives in the Planner Agent's execution path —
ExecutionAction.runinmindsearch/agent/graph.py— reachable viaPOST /solve, which fails to sanitize theinputsargument. - No authentication, privileges, or user interaction are required, making this exploitable by any attacker who can reach the endpoint over the network.
- The vendor did not respond to the disclosure, and no fixed version is currently available — the only mitigation is network isolation and sandboxing.
- Because MindSearch is an autonomous AI agent framework, a code-injection compromise can grant attackers the same tool access and credentials the agent itself holds.
- Organizations should audit for MindSearch 0.1.0 as both a direct deployment and a transitive dependency, and isolate any exposed instance immediately.