Vulnerability  ·  2026-10-05

InternLM MindSearch 0.1.0 unauthenticated remote code injection in Planner Agent (model output passed to unsandboxed exec())

VulnerabilityHigh impactGlobalCVE-2026-105135
NVD published CVE-2026-105135 (CVSS 10.0 critical) on 2026-10-04 for InternLM MindSearch 0.1.0. The planner agent is instructed to emit Python inside an interpreter block; ExecutionAction.run extracts model-written code and executes it via unsandboxed exec(), while the FastAPI service exposes an unauthenticated POST /solve bound to 0.0.0.0:8002. A public PoC gist proves end-to-end RCE with a real production model (DeepSeek-V4-Flash), running 'id' as uid=0 root in the container.
Any internet-exposed MindSearch deployment is trivially fully compromised without credentials: the attacker can read OPENAI_API_KEY / WEB_SEARCH_API_KEY from the process environment, read/write host and container files, plant implants, and use the process as an SSRF/proxy into the adjacent network. The CORS misconfiguration turns it into a drive-by attack on local developer instances. It is a classic agent-execution attack class with a working public PoC and no fix, so a defender must isolate or refactor the deployment.
Attacker POSTs to the unauthenticated /solve endpoint (default 0.0.0.0:8002) with a crafted prompt; the planner agent emits a Python interpreter block that ExecutionAction.run in mindsearch/agent/graph.py extracts via the first markdown fence and passes to Python exec() with process globals and full __builtins__. No sandbox, no AST allowlist, no HTTP auth. Public gist demonstrates root command execution via prompt only.
InternLM MindSearch v0.1.0 and all public versions through latest main (commit 7952c5f, 2026-08-22)
No vendor patch (vendor non-responsive). Authenticate POST /solve, bind to 127.0.0.1, do not publish 8002 on 0.0.0.0; do not exec() model output - dispatch only allowlisted structured WebSearchGraph operations; if a code interpreter is required, isolate in an unprivileged container with no secrets, no egress, seccomp and timeout. Gist: https://gist.github.com/DReazer/7ad46df9da73d0cf414276e4195b2183
NVD CVE-2026-105135Disclosure gist (executed PoC)VulDB entry 413352
See this in the live feed Explore related AI security and governance findings — updated every morning.
Open the feed →