Skip to finding
important · RCE

MindSearch contains an unrestricted Python exec sink, but its unauthenticated remote route remains unverified.

Affects

InternLM MindSearch, a Python-based AI search-agent application commonly exposed through a web service.

ExecutionAction.run strips optional Markdown fencing and passes its command argument directly to Python exec with server globals and locals.

Detail and 3 sources

The CNA record says a remote planner request reaches that sink, but the end-to-end dataflow from a stock unauthenticated request was not reproduced.

Chain to watch
Submit attacker-controlled input to a stock MindSearch 0.1.0 planner service.→↓Trace the planner-controlled command argument into ExecutionAction.run.→↓Confirm whether attacker-selected text reaches Python exec without authentication.→↓The sink is present, but the stock unauthenticated request-to-exec path remains unverified.
Unverified chainReplay the referenced exploit against stock MindSearch 0.1.0 while tracing the request handler, planner output and ExecutionAction.run argument.
Share this finding
Get it by email

The same brief, every morning. One email a day, nothing else.

Every finding here carries a source that was checked before it published. If something is wrong, write to admin@fullchain.sh — corrections are published on the day they affect.

Monday, October 5, 2026