Critical Progress DataDirect GenAI Flaw Lets Malicious OpenAPI Files Execute OS Commands
Progress warns CVE-2026-91140 lets malicious OpenAPI files run OS commands in DataDirect GenAI agents.
Progress disclosed CVE-2026-91140, a critical command-injection flaw in Early Access DataDirect Autonomous REST Connector AI Model Generator agent definitions. A filename taken from an OpenAPI or Swagger document is used in a shell temporary-file cleanup command without sufficient validation, so metacharacters can run arbitrary OS commands. Affected files are ARCGenAI-Generator.agent.md 2.0, ARCGenAI-Generator.prompt.md 1.0, and ARCGenAI-EntityGen.agent.md 1.0; corrected definitions are version 2.1. Progress reports no distinctive error on exploitation and urges customers to update before running the agents again.
- CVE-2026-91140 is command injection via OpenAPI or Swagger filenames.
- Early Access agent definitions pass filenames into a shell cleanup command.
- Three definition files must all be updated to version 2.1.
- Successful abuse could change developer workspaces or CI environments.
- No installer is required; pull the latest GitHub definitions.
Vulnerabilities mentionedAll →
- CVE-2026-911409.6—OS Command Injection via Malicious OpenAPI Docs in Progress ARCGenAI-Generator 2.0published · Progress Software Autonomous REST Connector GenAI Agents ARCGenAI-Generator
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2026-91140 | OS Command Injection via Malicious OpenAPI Docs in Progress ARCGenAI-Generator 2.0 Progress Software's Autonomous REST Connector GenAI Agents ARCGenAI-Generator version 2.0 contains an OS command injection flaw (CWE-78) in the shell-based temporary-file cleanup instructions it executes during code generation. An attacker crafts a malicious Swagger/OpenAPI document and gets a developer to run the generator against it; when the generator is invoked, attacker-controlled input reaches a shell command and arbitrary commands execute on the developer's machine. Successful exploitation gives full control of the victim workstation or CI runner (high impact to confidentiality, integrity, and availability, with scope escape beyond the tool itself), which can expose source code, credentials, and source-control or pipeline access. Only users who feed untrusted OpenAPI specifications into ARCGenAI-Generator 2.0 are exposed. There is no known public proof of concept, it is not in CISA's KEV catalog, and no exploitation has been observed. |
Full article452 words · extracted from cybersecuritynews.com · click to collapse
Progress disclosed critical command injection flaw CVE-2026-91140 in DataDirect Autonomous REST Connector AI Model Generator agents, allowing malicious OpenAPI or Swagger documents to execute arbitrary OS commands.
The security bulletin, published on October 6, 2026, covers Early Access agent definitions available through the public progress/datadirect-arc-ai-model-gen GitHub repository. Progress has released updated definitions and urges customers to retrieve them before running the agents again.
The vulnerability originates from a filename value derived from an OpenAPI or Swagger document. Affected agent definitions use this value in a shell operation without sufficient validation and quoting, allowing specially crafted input to change how the shell interprets the operation.
The vulnerability description identifies shell-based temporary-file cleanup instructions as the affected execution path. An attacker can supply a document containing shell metacharacters within the filename value.
When a developer invokes the vulnerable generator, those characters can cause the shell to execute attacker-controlled commands instead of treating the value only as a filename.
This makes document processing the attack entry point. The malicious content does not need to arrive as a standalone executable. Instead, an apparently ordinary API specification becomes dangerous when the affected agent passes document-derived data into a shell command.
Progress DataDirect GenAI Flaw
Successful exploitation can affect a developer workspace or a continuous integration environment where the agent runs. Progress warns that customers may observe unexpected files, commands, or other changes in these environments.
The vulnerability does not generate a specific product error message, meaning an obvious application warning cannot be relied upon to identify exploitation.
Progress identifies three affected files: ARCGenAI-Generator.agent.md version 2.0, ARCGenAI-Generator.prompt.md version 1.0, and ARCGenAI-EntityGen.agent.md version 1.0. These are agent and prompt definitions distributed through the project repository.
The corrected release updates all three definitions to version 2.1. Customers should check each file rather than assuming that replacing only the main generator definition addresses every affected component listed in the advisory.
Progress says the fix requires pulling the latest agent definitions from the repository. No installer, patch installation, or migration is required. The company strongly recommends completing this update before using the agents again.
Customers who previously processed untrusted or third-party OpenAPI or Swagger documents with affected definitions should review the associated workspace or CI environment for unexpected files and other signs of command execution.
This retrospective review is separate from updating the definitions because the advisory also addresses environments where potentially malicious documents were already processed. Customers with questions or concerns can open a Progress Technical Support case.
Stops threats before impact with 21 min faster MTTR. Integrate ANYRUN’s Sandbox in your SOC
Abinayahttps://cybersecuritynews.com/
Abi is a Security Editor and fellow reporter with Cyber Security News. She is covering various cyber security incidents happening in the Cyber Space.