Act nowDisclosed

Advisory · CVE-2026-105135

Unauthenticated RCE in InternLM MindSearch via unsandboxed interpreter exec()

MindSearch's unauthenticated POST /solve endpoint passes planner-agent Python straight to exec() with full builtins and process globals, giving any network attacker root code execution in the default Docker deployment.

Vendor
Shanghai AI Laboratory / InternLM
Product
MindSearch
Identifier / CWE
CVE-2026-105135
CWE-94, CWE-74
Action timing
Immediate
ELI5

Explain it like I’m five

MindSearch asks its AI planner to write Python code, then runs whatever the planner writes with the same permissions as the server. An attacker can type a malicious request, have the planner copy attack code into the answer, and the server runs it as root.

SIMPLIFIED_ATTACK_PATH04 STEPS
  1. 01Unauthenticated request

    An attacker with network reach to port 8002 sends a POST /solve request with crafted natural-language input; no credentials are required.

  2. 02Planner emits interpreter code

    The planner agent is instructed to emit Python inside an <|interpreter|> block on each planning turn, and the attacker's input steers it to include the payload.

  3. 03Code extracted and executed

    ExecutionAction.run extracts the first fenced code block from the model message and passes it to Python exec() with the process globals() and full __builtins__, no sandbox and no AST allowlist.

  4. 04Root command execution

    The payload runs with the privileges of the API worker process, which is root inside the official Docker image, enabling shell commands, file access, and credential theft.

What happened

CVE-2026-105135 is an unauthenticated remote code execution vulnerability in InternLM MindSearch, the open-source AI search-agent framework from Shanghai AI Laboratory. It is rated Critical at CVSS 10.0 and the exploit has been disclosed publicly. The NVD entry notes the vendor was contacted early but did not respond, and no patched release has been announced.

The MindSearch API exposes POST /solve with no authentication, binding by default to 0.0.0.0:8002. The planner agent is instructed to emit Python in an <|interpreter|> block on every planning turn. ExecutionAction.run in mindsearch/agent/graph.py extracts the first markdown code fence from the model’s message and passes it to Python’s exec() with the process globals() and unrestricted __builtins__. The only filtering is deleting a from ... import WebSearchGraph line, and the exec() runs before any graph validation, so the payload does not even need to be valid graph code.

The disclosure demonstrated end-to-end exploitation with a real production planner model: a crafted prompt steers the model to copy attacker commands into its interpreter block, and the server executes them, returning uid=0(root) inside the container. Default CORS is allow_origins=["*"] with credentials, so a malicious webpage can also target a developer’s local instance over 127.0.0.1:8002 without user interaction.

What to do

  1. Find every MindSearch deployment in your environment, including demos, research boxes, and locally running copies of the official Docker image.
  2. Do not expose the API to untrusted networks: stop publishing port 8002 publicly, bind the app to 127.0.0.1, and put the endpoint behind authentication (reverse proxy with auth or firewall rules).
  3. Because there is no vendor patch, treat any internet- or network-reachable instance as potentially compromised: inspect the host and container for unexpected processes, files, and outbound connections.
  4. Rotate credentials that the process could read from its environment (OPENAI_API_KEY, WEB_SEARCH_API_KEY, cloud keys) if the instance was reachable.
  5. Do not run the official image with root in production; long term, the interpreter path must be sandboxed or replaced with structured, allowlisted graph operations before the API is exposed again.

Management note

This is a Critical unauthenticated RCE with a published exploit, root in the default container, no patch, and an unresponsive vendor. Running AI-agent code that exec()s model output on an open port is one of the worst trust-boundary designs in current AI infrastructure. Any MindSearch instance on the network is a containment incident until it is isolated or retired.