Critical Progress DataDirect GenAI Flaw Lets OpenAPI Files Execute OS Commands
Key Takeaways A critical command injection vulnerability, CVE-2026-91140, has been identified in Progress DataDirect Autonomous REST Connector AI Model Generator agents. The flaw allows specially...
Key Takeaways
- A critical command injection vulnerability, CVE-2026-91140, has been identified in Progress DataDirect Autonomous REST Connector AI Model Generator agents.
- The flaw allows specially crafted OpenAPI or Swagger documents to execute arbitrary operating system commands.
- Affected components include specific agent and prompt definitions distributed via GitHub.
- Progress has released updated definitions (version 2.1) to mitigate the vulnerability.
- Users are urged to update immediately and review environments where untrusted documents were previously processed.
Progress has disclosed a severe command injection vulnerability, tracked as CVE-2026-91140, impacting its DataDirect Autonomous REST Connector AI Model Generator agents. This critical flaw enables malicious OpenAPI or Swagger documents to trigger the execution of arbitrary operating system commands, posing a significant risk to development and continuous integration environments.
Table Of Content
The security bulletin, issued on October 6, 2026, details the vulnerability within Early Access agent definitions distributed through the public progress/datadirect-arc-ai-model-gen GitHub repository. Progress has promptly released updated definitions and strongly advises all users to retrieve these fixes before continuing to use the affected agents.
Technical Details of the Flaw
The root cause of the vulnerability lies in how affected agent definitions process filename values derived from OpenAPI or Swagger documents. These values are incorporated into shell operations without adequate validation or proper quoting. This oversight allows an attacker to inject specially crafted input containing shell metacharacters, altering the intended interpretation of the shell command and enabling unauthorized command execution.
Specifically, the vulnerability exploits shell-based temporary-file cleanup instructions. An attacker can embed shell metacharacters within the filename value of an OpenAPI or Swagger document. When a developer invokes the vulnerable generator, these characters are interpreted by the shell as commands rather than part of a filename, leading to the execution of attacker-controlled instructions.
This mechanism makes the processing of API specification documents a direct entry point for attacks. Malicious content does not need to be a standalone executable; instead, seemingly benign API specifications become dangerous when the compromised agent feeds document-derived data into a shell command without proper sanitization.
Impact and Affected Components
Successful exploitation of this vulnerability can compromise a developer’s workstation or a continuous integration (CI) environment where the vulnerable agent operates. Progress has warned that customers might observe unexpected files, unauthorized commands, or other anomalous changes within these environments if exploited.
A key challenge in detection is that the vulnerability does not generate specific product error messages. This means that application warnings cannot be relied upon to identify ongoing exploitation, requiring more proactive monitoring for suspicious activity.
Progress identifies three specific files as affected: ARCGenAI-Generator.agent.md version 2.0, ARCGenAI-Generator.prompt.md version 1.0, and ARCGenAI-EntityGen.agent.md version 1.0. These are critical agent and prompt definitions distributed via the project’s GitHub repository.
The corrective release updates all three definitions to version 2.1. Users are advised to verify that all listed components have been updated, rather than assuming that replacing only the main generator definition will address the entire scope of the advisory.
What You Should Do
- Update Agent Definitions: Immediately pull the latest agent definitions from the Progress DataDirect ARC AI Model Generator GitHub repository. This update does not require an installer, patch, or migration.
- Verify All Components: Ensure that ARCGenAI-Generator.agent.md, ARCGenAI-Generator.prompt.md, and ARCGenAI-EntityGen.agent.md are all updated to version 2.1.
- Review Environments: If untrusted or third-party OpenAPI or Swagger documents were previously processed using affected definitions, thoroughly review the associated developer workspaces or CI environments for any unexpected files, command execution traces, or other signs of compromise.
- Contact Support: Customers with any questions or concerns regarding this vulnerability should open a case with Progress Technical Support.
Disclaimer: HackersRadar reports on cybersecurity threats and incidents for informational and awareness purposes only. We do not engage in hacking activities, data exfiltration, or the hosting or distribution of stolen or leaked information. All content is based on publicly available sources.



No Comment! Be the first one.