External risk intelligence

InternLM MindSearch Planner Agent Code Injection

CVE advisorySeverity: CRITICAL (CVSS 9.3)

CVE-2026-105135

The vulnerability exists in the Planner Agent component of an AI/search framework. While it is network-reachable, such components are typically integrated into backend services or internal orchestration layers rather than being deployed as direct internet-facing public endpoints.

Code Injection

Halo Surface Signal: 3 out of 5 — possibly public-facing.

External exposure likelihood

Horizon Alert

Summary of the vulnerability and why it matters

A vulnerability has been publicly disclosed in the Planner Agent component of InternLM MindSearch, which allows for remote code injection. While the vendor has not responded, the exploit is publicly available, raising concerns about potential misuse. The main concern is confirming the relevance and exposure of this component within our environment.

  • Code can be injected remotely.
  • Affects AI search and planning tools.
  • Confirm if this component is in use.

Attack Path

How an attacker could exploit the issue

An attacker can remotely trigger this vulnerability by manipulating the input arguments to the ExecutionAction.run function within the Planner Agent component. This manipulation can lead to code injection, allowing the attacker to execute arbitrary code.

  • Network access required for attack.
  • Manipulate function inputs to inject code.
  • Remote code execution.

Live Threat

Current exploitation, exposure, and threat context

The vulnerability in the Planner Agent component could allow remote attackers to inject and execute arbitrary code. This could affect the behavior of the service and potentially lead to unauthorized actions when the component is running with elevated privileges.

  • Service behavior and execution.
  • Remotely trigger code injection.
  • Undetected system compromise.

Operational Fix

Recommended remediation, mitigation, and detection steps

The Planner Agent component, if deployed, is likely managed by a platform or infrastructure team. Given the public exploit disclosure and lack of vendor response, an immediate inventory is critical to identify all instances, assess their exposure, and determine business criticality. Planning remediation should prioritize high-risk assets, potentially involving vendor coordination or temporary controls if immediate patching isn't feasible.

  • Platform/Infrastructure teams own remediation.
  • Verify deployed instances and exposure.
  • Plan remediation based on risk.

Supplementary metadata

Validate whether this threat affects your internet-facing exposure.

Halo Threat Intelligence helps prioritize remediation with Halo Surface Signal and H/A/L/O context. Start exposure validation with a free external attack surface trial.

Frequently asked questions

What is InternLM MindSearch?

InternLM MindSearch is an open-source framework designed for AI-driven search and complex task planning. It functions as an orchestration layer, where specialized agents process user queries and coordinate steps to retrieve and synthesize information. The vulnerable Planner Agent is the core component responsible for this high-level logic, acting as the brain that directs the flow of execution within the broader system.

How does CVE-2026-105135 cause code injection?

This vulnerability is classified as Improper Neutralization of Special Elements (CWE-74) and Improper Control of Generation of Code (CWE-94). It occurs because the Planner Agent does not properly validate data passed to the ExecutionAction.run function. By sending specially crafted inputs, an attacker can bypass intended logic constraints to execute unauthorized commands on the underlying host system, effectively turning the search tool into a vehicle for arbitrary code execution.

What triggers the Planner Agent vulnerability?

An attacker triggers this flaw by remotely submitting malicious input arguments that are processed by the ExecutionAction.run function. The system is only vulnerable when it parses these manipulated inputs. Legitimate, non-malicious interactions with the AI agent or tasks that do not involve passing unvalidated parameters to this specific function do not trigger the injection flaw.

How do I assess if I am at risk?

According to Halo Surface Signal, you should prioritize identifying where MindSearch is deployed. While the vulnerability is network-reachable, these agents are typically integrated into backend services or internal orchestration layers rather than exposed directly to the public internet. If your Planner Agent is isolated within an internal network, it is less accessible to external attackers than a public-facing endpoint.

What are the first steps to secure this service?

Start by performing an immediate inventory to locate all instances of MindSearch across your infrastructure. Since there is currently no vendor-provided patch, restrict access to the Planner Agent to authorized internal users only. Ensure the service runs with the least amount of privilege necessary to limit the potential impact if a compromise occurs, and consult with your platform team to monitor for suspicious input patterns.

References