Vulnerability
Published 2026-10-06
Verified 2026-10-07

Progress DataDirect CVE-2026-91140 (CVSS 9.6): Autonomous REST Connector GenAI agent definitions run attacker commands when a developer feeds them a crafted OpenAPI or Swagger file; fixed by pulling the version 2.1 definitions

Progress published a critical security bulletin on 6 October 2026 for CVE-2026-91140, an OS command injection flaw in the GenAI agent and prompt definitions for the DataDirect Autonomous REST Connector (ARC) AI Model Generator, distributed through the public progress/datadirect-arc-ai-model-gen GitHub repository as an Early Access feature. The generator takes a filename value from the OpenAPI or Swagger document it is given and uses it in a shell command for temporary-file cleanup without proper validation or quoting, so a document with shell metacharacters in that value runs commands on the developer's machine or the CI runner when someone invokes the generator. Progress rates it CVSS 3.1 9.6 (network, no privileges, user interaction required). The affected files are ARCGenAI-Generator.agent.md 2.0, ARCGenAI-Generator.prompt.md 1.0 and ARCGenAI-EntityGen.agent.md 1.0; all three are updated to 2.1. There is no installer or migration: the fix is pulling the latest definitions. Progress also tells anyone who already ran the agents on untrusted or third-party API specifications to review those workspaces and CI environments for unexpected files or commands, since the flaw produces no product error message. CISA's assessment records no known exploitation. Primary: Progress bulletin and the GitHub fix commit; wire: Cyber Security News (7 Oct).

Product
Progress DataDirect Autonomous REST Connector GenAI agents (AI Model Generator agent and prompt definitions)
Versions
ARCGenAI-Generator.agent.md 2.0, ARCGenAI-Generator.prompt.md 1.0, ARCGenAI-EntityGen.agent.md 1.0 (fixed in 2.1)
CVSS
Critical (CVSS 3.1, Progress)
Exploited in Australia?
unknown
Patch to
Pull the latest definitions from the progress/datadirect-arc-ai-model-gen repository and confirm all three files are at version 2.1 before running the agents again. If you previously ran them on API specifications from outside your organisation, review the developer workstation or CI runner for unexpected files, processes and outbound connections, and rotate secrets that environment could reach. Treat API specification files from third parties as untrusted input to any AI coding agent.

Primary: Progress — DataDirect Critical Security Alert Bulletin, CVE-2026-91140 (published 6 Oct 2026) · Vendor: GitHub — progress/datadirect-arc-ai-model-gen fix commit (definitions 2.1) · CVE: CVE-2026-91140 · Cyber Security News — Critical Progress DataDirect GenAI flaw lets malicious OpenAPI files execute OS commands (7 Oct 2026)

tech ai