CVE-2026-105135 explained: what the InternLM MindSearch 0 flaw means for your business

Introduction
CVE-2026-105135 is a security flaw in a part of InternLM MindSearch 0 called the Planner Agent. It lets someone send crafted input that gets run as code, from across a network, with no password needed. If your business runs InternLM MindSearch 0, or had a developer install it for you, keep reading.
Does this affect you?
The two-minute check
- Open the software and look for an About screen or startup message naming InternLM MindSearch 0 and a version number.
- Ask whoever set it up if it includes the Planner Agent component named in the advisory.
- Look in your server or project folder for a file called graph.py inside a folder named mindsearch/agent.
- If none of this looks familiar, ask your IT provider or developer whether this software runs anywhere in your business.
What the record does and does not tell us
The official record for this flaw lists no specific vendor or product versions as affected (NVD). That is unusual, and it means you can't rely on a vendor list to rule yourself out. The safest approach is to check your own installation directly, using the steps above. If you find InternLM MindSearch 0 anywhere in your systems, treat it as potentially affected until you confirm otherwise.
How bad is it, honestly?
What the official record says
This flaw carries a score of 10 out of 10 on the Common Vulnerability Scoring System (CVSS), rated critical (NVD). The scoring details show it can be reached over a network. It needs no special skill, no account, and no click from anyone inside your business. A successful attempt can also affect systems connected to the vulnerable one, not just the software itself (NVD).
The Exploit Prediction Scoring System (EPSS) puts exploitation probability at 0.77%, with a 54th percentile ranking (FIRST.org). That is a low chance of exploitation in the next 30 days. EPSS is a forecast of exploitation activity, not a measure of how severe the flaw is.
What that means for a business like yours
A critical, remotely reachable flaw that needs no login is worth taking seriously. If InternLM MindSearch 0 sits on a server reachable from the internet, anyone who finds it can try to use this flaw against you. The low EPSS number suggests wide automated attacks haven't appeared yet. That doesn't mean the risk is small, since the technical bar to attempt it is low.
What to do about it, step by step
If someone else manages your IT
If an outside provider manages your systems, send them a short message. Here is wording you can paste directly:
"Can you confirm if InternLM MindSearch 0 runs anywhere in our systems? If so, please check it against CVE-2026-105135. Please restrict it from public internet access until a fix exists. Let me know what you find."
If you manage it yourself
- Open a file browser on the computer, phone, or server you run InternLM MindSearch 0 on.
- Look for the file mindsearch/agent/graph.py named in the advisory.
- If you find it, disconnect that server from public internet access.
- Add a firewall rule that blocks unneeded inbound traffic to that machine.
- Restrict logins to that machine through privileged access controls.
- Ask your managed IT provider to add this flaw to their watch list.
How long you have
The vendor was contacted early about this disclosure but did not respond (NVD). That means there's no fix timeline to share right now. The record notes that exploit details have already been disclosed publicly and may be used (gist.github.com). It is not listed on the CISA Known Exploited Vulnerabilities (KEV) catalog, which tracks confirmed active attacks. Treat the exposure window as open-ended until a fix appears. Check the reference links below again in a few weeks for updates. If this flaw is later added to the KEV catalog, that is a clear signal to act fast.
How to check it actually worked
There's no vendor patch to install yet, so you can't confirm a fix is in place. What you can confirm is whether your interim protections are actually working.
- Confirm the server running InternLM MindSearch 0 no longer accepts connections from the open internet.
- Confirm only approved accounts can log in to that machine.
- Ask your IT provider to show you the firewall rule blocking access, not just tell you it exists.
- Re-check the reference links below for a vendor update, since none existed at the time of writing.
What to do if you can't patch right now
There is no patch to apply yet, so every option here is about reducing exposure, not removing the flaw.
- Restrict network access so only known, approved addresses can reach the software. This narrows who can try to exploit it, but it does not remove the underlying flaw.
- Turn on monitoring or endpoint detection and response (EDR) on that machine. This helps you notice unusual activity, but it will not stop a successful attempt by itself.
- Limit who can log in through privileged access controls. This reduces how far an attacker could move, but it does not block the initial exploit.
- Back up data connected to that system on a regular schedule. This won't prevent an attack, but it gives you a path to recover if one succeeds.
Frequently Asked Questions
Do I have to do anything if we only use this at home?
Yes. If you run InternLM MindSearch 0 on a home computer or personal server, the same exposure applies. The flaw doesn't care whether the machine sits in an office or a spare room.
Will restricting internet access break anything?
Blocking inbound public access to one server usually doesn't affect normal business tools. It may stop remote access you rely on, so check with whoever manages that connection first.
How do we know if we've already been affected?
The record doesn't list specific signs of compromise to look for. Ask your IT provider to review logs on any server running InternLM MindSearch 0 for unusual activity.
Does this touch our compliance obligations?
If the affected system handles patient data, review it against your HIPAA obligations. If it handles financial data, the same applies under the FTC Safeguards Rule.
When will a patch be available?
The record does not list a fix or a timeline, and the vendor has not responded to disclosure attempts. Keep checking the reference links below for updates.
If you're not sure whether InternLM MindSearch 0 is running anywhere in your business, or you want help locking it down while you wait on a fix, LayerLogix can check for you. We bring 20+ years of experience and 100% Texas-based support to businesses across Greater Houston, DFW, and Austin. Start with a free IT assessment or contact us directly.
Need Help With Cybersecurity?
LayerLogix provides expert cybersecurity solutions for businesses across Houston and nationwide.
Related Articles
Need Expert IT Support?
Let our team help your Houston business with enterprise-grade IT services and cybersecurity solutions.


