A critical new CVE hits InternLM's MindSearch - but check who's actually running it
A maximum-severity bug lets anyone with network access run arbitrary code on MindSearch servers, but the real question is how many of these research tools are exposed in the first place.
A newly catalogued vulnerability in MindSearch, an open-source search agent built by Shanghai AI Laboratory’s InternLM team, has landed a top-tier severity score. NVD’s entry lists CVE-2026-105135 as critical, and a technical write-up on GitHub Gist explains why: it’s about as bad as a bug can get, letting a stranger on the internet run their own code on your server with zero login required. The catch, as ever, is working out who is actually still running the vulnerable setup.
What the bug actually does
MindSearch works by having an AI “planner agent” write bits of Python to search the web and reason through answers, which the software then runs for real. According to the gist, the code sits behind a single HTTP endpoint, POST /solve, that ships with no authentication whatsoever - no password, no API key, nothing to flip on in a config file. Whatever Python the model generates between special tags gets handed straight to Python’s exec() function, with full access to the process’s global variables and built-in functions. There’s no sandbox and no filter checking what that code is allowed to do.
Put plainly: anyone who can reach the server’s network port can get it to execute arbitrary operating-system commands. The researcher says this was proven against a real, production-grade language model (DeepSeek-V4-Flash), not a toy test, and notes the official Docker image typically runs the whole thing as root - meaning a successful attacker could get full control of the machine, not a limited sandboxed slice of it. The service also defaults to listening on 0.0.0.0, i.e. open to any network interface, on port 8002.
The underlying technical causes are logged as two standard weakness categories: missing authentication on a critical function, and improper control of code generation (code injection) - the kind of combination that routinely scores at the very top of severity scales.
So who is actually at risk
This affects MindSearch version 0.1.0 and the project’s current main branch as of late August 2026, per the disclosure. It does not affect every AI chatbot, every “agent” framework, or InternLM’s other, better-known models - it’s specific to this particular search-agent tool and its exposed API.
The bigger unknown is exposure. MindSearch is a research-oriented project rather than a mainstream consumer product, and nothing in the public record so far indicates how many instances are actually sitting on the open internet with the default, unauthenticated setup, nor whether attackers are exploiting it in the wild. NVD’s record and the gist both describe the flaw and its mechanics in detail, but neither confirms active attacks, and there’s no patch release referenced in either source at the time of writing. Until a fix lands and uptake data emerges, “critical severity” describes how bad the bug is if exploited - not how likely that is for any given reader.
What to do about it
If you’re not running MindSearch yourself, there’s nothing to do. If you are - whether for research, a demo, or a side project - the advice from the disclosure is unambiguous: do not expose port 8002 directly to the internet, put proper authentication in front of /solve, and avoid running the service as root. Treat any instance currently reachable without a login as already compromised until proven otherwise, and watch for an official patch.
For everyone else, this is a reminder that “AI agent” tools which let models generate and execute their own code are only as safe as the fences built around that code - and right now, MindSearch’s fence has a hole in it.