<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:webfeeds="http://webfeeds.org/rss/1.0"><channel><title>MindSearch (0.1.0) - CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/products/mindsearch-0.1.0/</link><description>Trending threats, MITRE ATT&amp;CK coverage, and detection metadata. Fed continuously.</description><generator>Hugo</generator><language>en</language><managingEditor>hello@craftedsignal.io</managingEditor><webMaster>hello@craftedsignal.io</webMaster><lastBuildDate>Sun, 04 Oct 2026 09:01:35 +0000</lastBuildDate><atom:link href="https://feed.craftedsignal.io/products/mindsearch-0.1.0/feed.xml" rel="self" type="application/rss+xml"/><image><url>https://feed.craftedsignal.io/favicon-32x32.png</url><title>CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/</link><width>32</width><height>32</height></image><webfeeds:icon>https://feed.craftedsignal.io/favicon.svg</webfeeds:icon><item><title>Remote Code Injection in InternLM MindSearch via Planner Agent</title><link>https://feed.craftedsignal.io/briefs/2026-10-internlm-mindsearch-code-injection/</link><pubDate>Sun, 04 Oct 2026 09:01:35 +0000</pubDate><author>hello@craftedsignal.io</author><guid isPermaLink="true">https://feed.craftedsignal.io/briefs/2026-10-internlm-mindsearch-code-injection/</guid><description>InternLM MindSearch version 0.1.0 is vulnerable to remote code injection via the ExecutionAction.run function, allowing attackers to execute arbitrary code on the host system.</description><content:encoded><![CDATA[<p>InternLM MindSearch version 0.1.0 contains a critical remote code injection vulnerability. The issue resides within the ExecutionAction.run function located in mindsearch/agent/graph.py, which is part of the Planner Agent component. The vulnerability is triggered by manipulating the inputs argument during the execution flow. Because the Planner Agent fails to properly sanitize this input before processing, a remote attacker can inject and execute arbitrary system commands on the host environment. This vulnerability (CVE-2026-105135) has been publicly disclosed, and given the nature of the flaw, it is trivial to exploit. The vendor has been unresponsive to disclosure efforts, and no security patches are currently available to remediate this issue.</p>
<h2 id="impact">Impact</h2>
<p>Successful exploitation of CVE-2026-105135 allows an unauthenticated remote attacker to gain full code execution capabilities on the host system running the MindSearch service. This may lead to total system compromise, data exfiltration, or the deployment of additional malicious payloads. Organizations deploying InternLM MindSearch 0.1.0 are at high risk until the vulnerable component is isolated or updated.</p>
<h2 id="recommendation">Recommendation</h2>
<ol>
<li>Inventory all instances of InternLM MindSearch 0.1.0 within the environment and restrict network access to these services until a vendor patch is available.</li>
<li>Implement strict input validation or web application firewall (WAF) rules to inspect the inputs argument passed to the Planner Agent's ExecutionAction.run function.</li>
<li>Monitor process creation logs for unexpected child processes originating from the MindSearch service process (e.g., cmd.exe, /bin/sh, /bin/bash).</li>
</ol>
]]></content:encoded><category domain="severity">critical</category><category domain="type">advisory</category><category>code-injection</category><category>vulnerability</category><category>rce</category></item></channel></rss>