Critical Progress DataDirect GenAI Flaw Lets Attackers Execute Arbitrary OS Commands
Progress warns CVE-2026-91140 lets crafted OpenAPI files run OS commands in DataDirect GenAI agents.
Progress disclosed CVE-2026-91140, a critical command-injection flaw in early-access DataDirect Autonomous REST Connector AI Model Generator agents. A filename taken from an OpenAPI or Swagger document is passed into a shell without adequate validation, so a crafted document can run arbitrary OS commands. Affected files are ARCGenAI-Generator.agent.md 2.0, ARCGenAI-Generator.prompt.md 1.0, and ARCGenAI-EntityGen.agent.md 1.0; version 2.1 fixes them. Progress reports no CVSS score and no evidence of active exploitation, and impact is limited to generator workspaces and CI systems.