OS Command Injection via Malicious OpenAPI Docs in Progress ARCGenAI-Generator 2.0
AI analysis
Progress Software's Autonomous REST Connector GenAI Agents ARCGenAI-Generator version 2.0 contains an OS command injection flaw (CWE-78) in the shell-based temporary-file cleanup instructions it executes during code generation. An attacker crafts a malicious Swagger/OpenAPI document and gets a developer to run the generator against it; when the generator is invoked, attacker-controlled input reaches a shell command and arbitrary commands execute on the developer's machine. Successful exploitation gives full control of the victim workstation or CI runner (high impact to confidentiality, integrity, and availability, with scope escape beyond the tool itself), which can expose source code, credentials, and source-control or pipeline access. Only users who feed untrusted OpenAPI specifications into ARCGenAI-Generator 2.0 are exposed. There is no known public proof of concept, it is not in CISA's KEV catalog, and no exploitation has been observed.
What to do: Treat every Swagger/OpenAPI document as untrusted input: never run ARCGenAI-Generator 2.0 against specs downloaded from unvetted URLs, forked repositories, or third parties. Run the generator only inside an isolated container or VM with no credentials, SSH keys, or source-control tokens until a patched version is available from Progress (none is named in the advisory, so confirm directly with Progress support). If untrusted specs were processed, review the affected machine and CI logs for unexpected shell commands, spawned processes, or modified files and rotate any credentials accessible from it.
Affected
| Progress Software Autonomous REST Connector GenAI Agents ARCGenAI-Generator | — |
Estimated exposure
nichelikely hundreds to low thousands of developer workstations and CI runners (estimate; no published adoption figures) — ARCGenAI-Generator is a specialized developer utility within Progress's Autonomous REST Connector ecosystem rather than a deployed server product, so exposure is confined to machines that actually invoke the generator, and no install…
Description
An OS command injection vulnerability in the shell-based temporary-file cleanup instructions in Progress Software Autonomous REST Connector GenAI Agents ARCGenAI-Generator version 2.0 allows an attacker who supplies a crafted Swagger/OpenAPI document to execute arbitrary commands on a developer's machine when a user invokes the generator.