Critical severity9.6NVD Advisory· Published Oct 6, 2026
CVE-2026-91140
CVE-2026-91140
Description
An OS command injection vulnerability in the shell-based temporary-file cleanup instructions in Progress Software Autonomous REST Connector GenAI Agents ARCGenAI-Generator version 2.0 allows an attacker who supplies a crafted Swagger/OpenAPI document to execute arbitrary commands on a developer's machine when a user invokes the generator.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
2- Range: 2.0
- Range: 2.0
Patches
Vulnerability mechanics
References
2News mentions
0No linked articles in our index yet.