VYPR
patchPublished Oct 7, 2026· 1 source

Progress DataDirect GenAI Flaw Allows OS Command Execution via Malicious OpenAPI Files

A critical command injection vulnerability (CVE-2026-91140) in Progress DataDirect's Autonomous REST Connector AI Model Generator agents allows attackers to execute arbitrary OS commands by submitting specially crafted OpenAPI or Swagger files.

Progress has disclosed a critical command injection vulnerability, identified as CVE-2026-91140, within its DataDirect Autonomous REST Connector AI Model Generator agents. This flaw enables attackers to execute arbitrary operating system commands by leveraging malicious OpenAPI or Swagger documents. The vulnerability was detailed in a security bulletin released on October 6, 2026, and affects early access agent definitions available through the public progress/datadirect-arc-ai-model-gen GitHub repository.

The root cause of the vulnerability lies in how the affected agent definitions process a filename value derived from an OpenAPI or Swagger document. This value is used in shell operations without adequate validation or proper quoting. Consequently, specially crafted input within the filename can manipulate the shell's interpretation of the operation, leading to unintended command execution. The vulnerability specifically targets shell-based temporary-file cleanup routines within the affected agents.

Attackers can exploit this by providing an OpenAPI or Swagger document that contains shell metacharacters within the filename field. When a developer invokes the vulnerable generator with such a document, these metacharacters can cause the shell to execute commands controlled by the attacker, rather than treating the input solely as a filename. This means the attack vector is the processing of the document itself, with no need for a separate executable file.

Successful exploitation of CVE-2026-91140 can have significant consequences, particularly within developer workspaces or continuous integration (CI) environments where the affected agents are run. Progress warns that compromised systems may exhibit unexpected files, executed commands, or other anomalous activities. The vulnerability does not produce a distinct product error message, making it difficult to detect exploitation through application-level warnings alone.

Progress has identified three specific affected files: ARCGenAI-Generator.agent.md version 2.0, ARCGenAI-Generator.prompt.md version 1.0, and ARCGenAI-EntityGen.agent.md version 1.0. These files represent agent and prompt definitions distributed via the project's GitHub repository. The fix involves updating all three definitions to version 2.1. Customers are advised to verify and update each of these files, as replacing only the main generator definition may not fully address the vulnerability across all components.

To remediate the vulnerability, customers are instructed to pull the latest agent definitions from the GitHub repository. Progress states that no specific installer, patch installation, or migration process is required beyond updating these definition files. The company strongly urges users to perform this update before continuing to use the affected agents.

Furthermore, Progress recommends that customers who have previously processed untrusted or third-party OpenAPI or Swagger documents with the vulnerable definitions should conduct a retrospective review of their associated workspaces or CI environments. This review should look for any signs of unexpected files or command execution, as the update addresses environments where potentially malicious documents may have already been processed.

Customers experiencing issues or requiring further assistance are encouraged to open a case with Progress Technical Support. This vulnerability highlights the ongoing risks associated with processing external data within AI-powered development tools, emphasizing the need for robust input validation and security best practices.

Synthesized by Vypr AI
Progress DataDirect GenAI Flaw Allows OS Command Execution via Malicious OpenAPI Files · VYPR