important · RCE
MindSearch contains an unrestricted Python exec sink, but its unauthenticated remote route remains unverified.
Affects
InternLM MindSearch, a Python-based AI search-agent application commonly exposed through a web service.
ExecutionAction.run strips optional Markdown fencing and passes its command argument directly to Python exec with server globals and locals.
Detail and 3 sources
The CNA record says a remote planner request reaches that sink, but the end-to-end dataflow from a stock unauthenticated request was not reproduced.
Chain to watch
Submit attacker-controlled input to a stock MindSearch 0.1.0 planner service.→↓Trace the planner-controlled command argument into ExecutionAction.run.→↓Confirm whether attacker-selected text reaches Python exec without authentication.→↓The sink is present, but the stock unauthenticated request-to-exec path remains unverified.
Unverified chainReplay the referenced exploit against stock MindSearch 0.1.0 while tracing the request handler, planner output and ExecutionAction.run argument.