Critical Progress DataDirect GenAI Flaw Lets Attackers Execute Arbitrary OS Commands
Progress warns CVE-2026-91140 lets crafted OpenAPI files run OS commands in DataDirect GenAI agents.
Progress disclosed CVE-2026-91140, a critical command-injection flaw in early-access DataDirect Autonomous REST Connector AI Model Generator agents. A filename taken from an OpenAPI or Swagger document is passed into a shell without adequate validation, so a crafted document can run arbitrary OS commands. Affected files are ARCGenAI-Generator.agent.md 2.0, ARCGenAI-Generator.prompt.md 1.0, and ARCGenAI-EntityGen.agent.md 1.0; version 2.1 fixes them. Progress reports no CVSS score and no evidence of active exploitation, and impact is limited to generator workspaces and CI systems.
- CVE-2026-91140 is command injection in early-access DataDirect GenAI agent definitions.
- Crafted OpenAPI or Swagger filenames can reach a shell without proper quoting.
- Three agent and prompt files before version 2.1 are affected.
- Progress says replace the GitHub definitions; no installer is required.
- The bulletin gives no CVSS score and no evidence of active attacks.
Vulnerabilities mentionedAll →
- CVE-2026-911409.6—OS Command Injection via Malicious OpenAPI Docs in Progress ARCGenAI-Generator 2.0published · Progress Software Autonomous REST Connector GenAI Agents ARCGenAI-Generator
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2026-91140 | OS Command Injection via Malicious OpenAPI Docs in Progress ARCGenAI-Generator 2.0 Progress Software's Autonomous REST Connector GenAI Agents ARCGenAI-Generator version 2.0 contains an OS command injection flaw (CWE-78) in the shell-based temporary-file cleanup instructions it executes during code generation. An attacker crafts a malicious Swagger/OpenAPI document and gets a developer to run the generator against it; when the generator is invoked, attacker-controlled input reaches a shell command and arbitrary commands execute on the developer's machine. Successful exploitation gives full control of the victim workstation or CI runner (high impact to confidentiality, integrity, and availability, with scope escape beyond the tool itself), which can expose source code, credentials, and source-control or pipeline access. Only users who feed untrusted OpenAPI specifications into ARCGenAI-Generator 2.0 are exposed. There is no known public proof of concept, it is not in CISA's KEV catalog, and no exploitation has been observed. |
Full article492 words · extracted from gbhackers.com · click to collapse
Progress has disclosed a critical command injection vulnerability in the Early Access Release of its DataDirect Autonomous REST Connector AI Model Generator agents.
This vulnerability, tracked as CVE-2026-91140, allows specially crafted OpenAPI or Swagger documents to execute arbitrary operating system commands within the environment running an affected agent.
The security bulletin, dated October 6, 2026, identifies the vulnerable agent and prompt definitions available through the public GitHub repository at progress/datadirect-arc-ai-model-gen. Progress has provided updated definitions and urges customers to download them before using the agents again.
Progress DataDirect GenAI Flaw
According to the bulletin, the vulnerability arises from a filename value taken from an OpenAPI or Swagger document. Affected agent definitions utilize this value in a shell operation without adequate validation and quoting.
An attacker could construct a document containing shell metacharacters that modify how the shell interprets the operation. Instead of treating the derived value purely as a filename, the shell may execute attacker-controlled commands.
Exploitation relies on an affected agent processing a malicious document, which could occur in a developer workspace or a continuous integration environment. This limits the impact to systems used to generate connector models.
The repository describes a Copilot-based workflow that converts Swagger and OpenAPI specifications into DataDirect Autonomous REST Connector .rest configuration files. This process supports generation through VS Code Copilot Chat and GitHub Copilot CLI, followed by manual review, validation, and launch steps.
Affected Definitions and Fixes
Progress lists three components that are affected:
- ARCGenAI-Generator.agent.md, version 2.0
- ARCGenAI-Generator.prompt.md, version 1.0
- ARCGenAI-EntityGen.agent.md, version 1.0
Version 2.1 of each definition addresses this vulnerability. The remediation involves retrieving the latest agent definitions from the repository. Progress states that no installer, patch installation, or migration is required.
The EntityGen component is an internal sub-agent invoked automatically by the Generator. As a result, simply reviewing the top-level generation definition may overlook another component explicitly included in the vendor’s list of affected versions. The repository also warns users not to invoke the entity sub-agent directly.
This vulnerability does not trigger a specific product error message. Instead, customers may notice unexpected files, commands, or other changes in the workspace or CI environment where an affected agent processed a crafted document.
Customers who have previously utilized vulnerable definitions with untrusted or third-party specifications should inspect those environments for unexpected files and other signs of command execution.
Current repository documentation states that values from Swagger and OpenAPI fields must be treated as untrusted input, rather than executable instructions. It also mentions that the Generator will pause for clarification when filename derivation includes unsafe path-like characters.
The bulletin does not provide a CVSS score, exploitation statistics, or evidence of active attacks. Its immediate operational priority is to update all three definitions before running any further generation.
Stops Cyber threats before impact with 21 min faster MTTR. Integrate ANYRUN’s Sandbox in your SOC.
Divya is a Senior Journalist at GBhackers covering Cyber Attacks, Threats, Breaches, Vulnerabilities and other happenings in the cyber world.