Cyber & AI intelligence
Wasteland.
Briefs indexed3004
Issues30
Published Mondays07:30 CT
⚡ Active KEV CVE-2026-105135 2026-10-04

Critical Code Injection in InternLM MindSearch 0.1.0 Planner Agent (CVE-2026-105135)

"CVE-2026-105135 is a critical, remotely exploitable code injection flaw in the Planner Agent component of InternLM MindSearch 0.1.0; a public exploit has been disclosed and the vendor has not responded."

CVE-2026-105135 is a critical, remotely exploitable code injection flaw in the Planner Agent component of InternLM MindSearch 0.1.0; a public exploit has been disclosed and the vendor has not responded.

What Is It

CVE-2026-105135 is a code injection vulnerability in InternLM MindSearch version 0.1.0. It affects the ExecutionAction.run function in mindsearch/agent/graph.py, which is part of the Planner Agent component. An attacker can manipulate the inputs argument to inject code. The CNA classifies the weakness as CWE-74 (Injection) and CWE-94 (Code Injection).

VulDB, acting as CNA, published the record on 2026-10-04. Its NVD status is "Received," so NVD has not finished its own analysis yet.

Why It Matters

The CNA gives this vulnerability its highest severity ratings:

The attack works over the network. It needs no authentication, no user interaction and no special conditions. A successful attack has a high impact on confidentiality, integrity and availability, and the scope is rated as changed.

According to the record, the exploit has been publicly disclosed and may be used. The CISA Known Exploited Vulnerabilities (KEV) catalog has no entry for this CVE, so CISA has not confirmed active exploitation.

What's Vulnerable

The record lists no other affected versions.

Patch Status

The source material does not mention a patch or fixed version. According to the disclosure, the vendor was contacted early but did not respond. There is no CISA KEV entry, so no federal required action or due date applies.

If you run MindSearch 0.1.0, consider it exposed until InternLM releases a fix. Watch the references below for updates.

Sources