Progress DataDirect GenAI flaw allows OS command execution
CVE-2026-91140 lets malicious OpenAPI filenames run OS commands in early-access DataDirect GenAI agents; update definitions to 2.1.
Progress disclosed CVE-2026-91140, a critical command-injection flaw in early-access DataDirect Autonomous REST Connector AI Model Generator agent definitions. A filename taken from an OpenAPI or Swagger document is used in a shell temporary-file cleanup command without sufficient validation, so metacharacters in a crafted document can run arbitrary OS commands. Affected files are ARCGenAI-Generator.agent.md 2.0, ARCGenAI-Generator.prompt.md 1.0, and ARCGenAI-EntityGen.agent.md 1.0; version 2.1 corrects them, and Progress says no installer is required—customers should replace the GitHub definitions before running the agents again. One source says Progress reports no CVSS score and no evidence of active exploitation, and that impact is limited to generator workspaces and CI systems; the other says successful abuse leaves no distinctive error and could change developer workspaces or CI environments. Both agree the fix is the version 2.1 definitions.
- CVE-2026-91140 is a critical command-injection flaw in Progress Early Access DataDirect Autonomous REST Connector AI Model Generator agent definitions.
- A filename taken from an OpenAPI or Swagger document is passed into a shell temporary-file cleanup command without sufficient validation, so metacharacters can run arbitrary OS commands.
- Affected files are ARCGenAI-Generator.agent.md 2.0, ARCGenAI-Generator.prompt.md 1.0, and ARCGenAI-EntityGen.agent.md 1.0; corrected definitions are version 2.1.
- Progress says no installer is required; customers should pull the latest GitHub definitions and update before running the agents again.
- One report says Progress gives no CVSS score and no evidence of active exploitation; another says successful abuse leaves no distinctive error.
- Impact is described as limited to generator or developer workspaces and CI systems.
Coverage timelineoldest first · each row is one article
- · 2d agoCritical Progress DataDirect GenAI Flaw Lets Malicious OpenAPI Files Execute OS Commands
Cyber Security News· 55
Progress warns CVE-2026-91140 lets malicious OpenAPI files run OS commands in DataDirect GenAI agents.
- · 1d agoCritical Progress DataDirect GenAI Flaw Lets Attackers Execute Arbitrary OS Commands
GBHackers· 58
Progress warns CVE-2026-91140 lets crafted OpenAPI files run OS commands in DataDirect GenAI agents.
Vulnerabilities in this storyAll →
- CVE-2026-911409.6—OS Command Injection via Malicious OpenAPI Docs in Progress ARCGenAI-Generator 2.0published · Progress Software Autonomous REST Connector GenAI Agents ARCGenAI-Generator
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2026-91140 | OS Command Injection via Malicious OpenAPI Docs in Progress ARCGenAI-Generator 2.0 Progress Software's Autonomous REST Connector GenAI Agents ARCGenAI-Generator version 2.0 contains an OS command injection flaw (CWE-78) in the shell-based temporary-file cleanup instructions it executes during code generation. An attacker crafts a malicious Swagger/OpenAPI document and gets a developer to run the generator against it; when the generator is invoked, attacker-controlled input reaches a shell command and arbitrary commands execute on the developer's machine. Successful exploitation gives full control of the victim workstation or CI runner (high impact to confidentiality, integrity, and availability, with scope escape beyond the tool itself), which can expose source code, credentials, and source-control or pipeline access. Only users who feed untrusted OpenAPI specifications into ARCGenAI-Generator 2.0 are exposed. There is no known public proof of concept, it is not in CISA's KEV catalog, and no exploitation has been observed. |