rootpwn

critical · CVSS v3 10 · CVSS v4 10 · EPSS 0.0077

CVE-2026-105135

A vulnerability has been found in InternLM MindSearch 0.1.0. This issue affects the function ExecutionAction.run of the …

Description

A vulnerability has been found in InternLM MindSearch 0.1.0. This issue affects the function ExecutionAction.run of the file mindsearch/agent/graph.py of the component Planner Agent. The manipulation of the argument inputs leads to code injection. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.

Scores

Severity
critical
CVSS v2
10
CVSS v3
10
CVSS v4
10
EPSS
0.0077

← All CVEs