CVE-2026-105135 | InternLM MindSearch 0.1.0 Planner Agent graph.py ExecutionAction.run inputs code injection
A vulnerability, which was classified as very critical, has been found in InternLM MindSearch 0.1.0. This issue affects the function ExecutionAction.run of the file mindsearch/agent/graph.py of the component Planner Agent. The manipulation of the argument inputs leads to code injection.
This vulnerability is documented as CVE-2026-105135. The attack can be initiated remotely. Additionally, an exploit exists.
The vendor was contacted early about this disclosure but did not respond in any way.VulDB Recent EntriesRead More