MindSearch hit by critical code-injection flaw
CVE-2026-105135 exposes an unauthenticated remote code-execution flaw in MindSearch 0.1.0’s Planner Agent. Attackers who can reach the `/solve` endpoint may execute arbitrary Python code through unsandboxed planner output.
This is a severe trust-boundary failure in an agent framework: model-generated code is treated as executable server code without authentication or sandboxing.
- –Public exploit details demonstrate command execution inside default deployments
- –Exposed API instances may leak environment secrets, alter files, or enable lateral movement
- –Docker configurations running as root substantially amplify impact
- –Operators should isolate port 8002, add authentication, and disable unsandboxed `exec()`
- –The incident underscores why agent frameworks need structured tool calls instead of free-form code execution
DISCOVERED
56m ago
2026-10-05
PUBLISHED
1h ago
2026-10-05
RELEVANCE
AUTHOR
DailyDarkWeb