SECURITYCRITICALCVE-2026-105135

CVE-2026-105135: InternLM MindSearch Planner Agent Code Injection

An unauthenticated code injection flaw in MindSearch's Planner Agent lets remote attackers execute arbitrary code via the /solve endpoint.

Dylan H.

Security Team

October 4, 2026
6 min read
CVE-2026-105135: InternLM MindSearch Planner Agent Code Injection

Critical severity

Rated critical. Prioritise patching — see the remediation guidance below.

Affected Products

  • InternLM MindSearch — version 0.1.0

Overview

A maximum-severity, CVSS 10.0 code injection vulnerability has been disclosed in InternLM MindSearch, an open-source AI search-agent framework that plans and executes multi-step web research tasks. Tracked as CVE-2026-105135 and classified under CWE-74 (Injection) and CWE-94 (Code Injection), the flaw sits in MindSearch's Planner Agent component and allows a remote, unauthenticated attacker to execute arbitrary code on any server running the affected version.

The vulnerable code path is the ExecutionAction.run function in mindsearch/agent/graph.py, reachable through the framework's POST /solve endpoint. The Planner Agent passes the request's inputs argument into this execution routine without adequately validating or sanitizing it, so an attacker who crafts a malicious inputs payload can inject code that the agent's execution step will run directly on the host.

The vulnerability affects MindSearch 0.1.0, was published on October 4, 2026, and according to reporting on the disclosure, the vendor was contacted ahead of publication but did not respond. No fixed version has been identified as of this writing, and the CVE is not currently listed in CISA's Known Exploited Vulnerabilities (KEV) catalog, though sources differ on whether proof-of-concept exploit code is already circulating.


Technical Details

FieldValue
CVE IDCVE-2026-105135
CWECWE-74 (Injection), CWE-94 (Code Injection)
SeverityCritical
CVSS 3.1 Score10.0
CVSS 3.1 VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
Attack VectorNetwork (/solve endpoint)
AuthenticationNone required
Privileges RequiredNone
User InteractionNone
Affected SoftwareInternLM MindSearch 0.1.0
Fixed VersionNone identified at time of publication — vendor unresponsive

How It Works

MindSearch's Planner Agent decomposes a user's research query into an execution graph of sub-tasks, then runs each step through ExecutionAction.run in mindsearch/agent/graph.py. That function accepts an inputs argument intended to carry the step's parameters, but the framework does not sufficiently restrict or escape what that argument can contain before it reaches the underlying execution logic.

An unauthenticated attacker who sends a crafted request to POST /solve with a malicious inputs value can have arbitrary code run directly by the Planner Agent — with the full confidentiality, integrity, and availability impact reflected in the CVSS vector's C:H/I:H/A:H rating. No session, API key, or prior interaction is needed; reachability to the endpoint is the only prerequisite.

Why Agentic AI Frameworks Raise the Stakes

MindSearch is designed to autonomously plan and execute multi-step tasks, often with access to search tools, code execution, or other connected services. A code injection bug in the component responsible for actually running those planned steps doesn't just compromise the application — it hands the attacker the same execution capability the agent itself has, which in many deployments includes outbound network access, file system access, and any credentials the agent process holds for its downstream tools.


Impact Assessment

Impact AreaDescription
Remote Code ExecutionUnauthenticated attacker can execute arbitrary code via the Planner Agent's execution path
Credential/Data ExposureCode execution on the host can expose any API keys or credentials the MindSearch process holds for its connected tools
Lateral MovementA compromised agent host with outbound network access or tool integrations can be used to pivot into other connected systems
No Vendor Patch YetThe vendor did not respond to disclosure, leaving no official fixed version to upgrade to as of publication
Low Bar to ExploitNo authentication, privileges, or user interaction required — only network reachability to /solve
AI Supply Chain ExposureAny product or internal tool that embeds MindSearch as a dependency inherits this vulnerability

Who Is At Risk

Any organization running MindSearch 0.1.0, whether as a standalone deployment or embedded as a dependency inside a larger AI product, is at risk if the /solve endpoint is reachable from an untrusted network. Given the framework's purpose — autonomous research agents that often run with broad tool access — successful exploitation can be a stepping stone into whatever systems the agent itself is permitted to touch.


Mitigation

Immediate Actions

  • Take affected MindSearch instances off any untrusted network (including the public internet) until a fix is available; there is currently no patched version to upgrade to.
  • Audit MindSearch usage across your environment, including as a transitive dependency in other AI tooling, to confirm whether version 0.1.0 is in use.
  • Review logs for unexpected requests to the /solve endpoint, especially payloads containing unusual inputs values or shell/code-like syntax.

For Developers Embedding MindSearch

  • Do not expose the Planner Agent's /solve endpoint directly to untrusted callers; place it behind an authenticated proxy or gateway at minimum until an upstream fix lands.
  • Run MindSearch inside a sandboxed, least-privilege environment (restricted file system, no credentials beyond what a single task strictly needs) so a code-injection compromise can't reach broader infrastructure.
  • Track the upstream project for a patched release, and watch for a response from the maintainers given the current lack of vendor engagement on this disclosure.

For Security Teams

  • Add InternLM MindSearch to AI/ML software inventories — treat agentic AI frameworks with execution capabilities as high-value targets requiring the same scrutiny as any other network-facing service.
  • Monitor for public proof-of-concept exploit code and for this CVE's addition to CISA's KEV catalog, and prioritize isolation over waiting for KEV listing given the unauthenticated, maximum-severity profile.
  • Flag any internal AI agent framework that executes model-planned code paths for a security review of its input-handling boundaries, independent of this specific CVE.

Key Takeaways

  1. CVE-2026-105135 is a CVSS 10.0 Critical code injection vulnerability in InternLM MindSearch 0.1.0, classified under CWE-74/CWE-94.
  2. The flaw lives in the Planner Agent's execution path — ExecutionAction.run in mindsearch/agent/graph.py — reachable via POST /solve, which fails to sanitize the inputs argument.
  3. No authentication, privileges, or user interaction are required, making this exploitable by any attacker who can reach the endpoint over the network.
  4. The vendor did not respond to the disclosure, and no fixed version is currently available — the only mitigation is network isolation and sandboxing.
  5. Because MindSearch is an autonomous AI agent framework, a code-injection compromise can grant attackers the same tool access and credentials the agent itself holds.
  6. Organizations should audit for MindSearch 0.1.0 as both a direct deployment and a transitive dependency, and isolate any exposed instance immediately.

Sources