{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/cpes/cpe2.3ainternlmmindsearch0.1.0/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":["cpe:2.3:a:internlm:mindsearch:0.1.0:*:*:*:*:*:*:*"],"_cs_cves":[{"cvss":10,"id":"CVE-2026-105135"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["MindSearch (0.1.0)"],"_cs_severities":["critical"],"_cs_tags":["code-injection","vulnerability","rce"],"_cs_type":"advisory","_cs_vendors":["InternLM"],"content_html":"\u003cp\u003eInternLM MindSearch version 0.1.0 contains a critical remote code injection vulnerability. The issue resides within the ExecutionAction.run function located in mindsearch/agent/graph.py, which is part of the Planner Agent component. The vulnerability is triggered by manipulating the inputs argument during the execution flow. Because the Planner Agent fails to properly sanitize this input before processing, a remote attacker can inject and execute arbitrary system commands on the host environment. This vulnerability (CVE-2026-105135) has been publicly disclosed, and given the nature of the flaw, it is trivial to exploit. The vendor has been unresponsive to disclosure efforts, and no security patches are currently available to remediate this issue.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation of CVE-2026-105135 allows an unauthenticated remote attacker to gain full code execution capabilities on the host system running the MindSearch service. This may lead to total system compromise, data exfiltration, or the deployment of additional malicious payloads. Organizations deploying InternLM MindSearch 0.1.0 are at high risk until the vulnerable component is isolated or updated.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003col\u003e\n\u003cli\u003eInventory all instances of InternLM MindSearch 0.1.0 within the environment and restrict network access to these services until a vendor patch is available.\u003c/li\u003e\n\u003cli\u003eImplement strict input validation or web application firewall (WAF) rules to inspect the inputs argument passed to the Planner Agent's ExecutionAction.run function.\u003c/li\u003e\n\u003cli\u003eMonitor process creation logs for unexpected child processes originating from the MindSearch service process (e.g., cmd.exe, /bin/sh, /bin/bash).\u003c/li\u003e\n\u003c/ol\u003e\n","date_modified":"2026-10-04T09:01:35Z","date_published":"2026-10-04T09:01:35Z","id":"https://feed.craftedsignal.io/briefs/2026-10-internlm-mindsearch-code-injection/","summary":"InternLM MindSearch version 0.1.0 is vulnerable to remote code injection via the ExecutionAction.run function, allowing attackers to execute arbitrary code on the host system.","title":"Remote Code Injection in InternLM MindSearch via Planner Agent","url":"https://feed.craftedsignal.io/briefs/2026-10-internlm-mindsearch-code-injection/"}],"language":"en","title":"CraftedSignal Threat Feed - Cpe:2.3:a:internlm:mindsearch:0.1.0:*:*:*:*:*:*:*","version":"https://jsonfeed.org/version/1.1"}