Critical Progress DataDirect GenAI Flaw Lets Malicious OpenAPI Files Execute OS Commands
Progress warns CVE-2026-91140 lets malicious OpenAPI files run OS commands in DataDirect GenAI agents.
Progress disclosed CVE-2026-91140, a critical command-injection flaw in Early Access DataDirect Autonomous REST Connector AI Model Generator agent definitions. A filename taken from an OpenAPI or Swagger document is used in a shell temporary-file cleanup command without sufficient validation, so metacharacters can run arbitrary OS commands. Affected files are ARCGenAI-Generator.agent.md 2.0, ARCGenAI-Generator.prompt.md 1.0, and ARCGenAI-EntityGen.agent.md 1.0; corrected definitions are version 2.1. Progress reports no distinctive error on exploitation and urges customers to update before running the agents again.