Critical Progress DataDirect GenAI Flaw Lets Malicious OpenAPI Files Execute OS Commands

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com


Progress disclosed critical command injection flaw CVE-2026-91140 in DataDirect Autonomous REST Connector AI Model Generator agents, allowing malicious OpenAPI or Swagger documents to execute arbitrary OS commands.

The security bulletin, published on October 6, 2026, covers Early Access agent definitions available through the public progress/datadirect-arc-ai-model-gen GitHub repository. Progress has released updated definitions and urges customers to retrieve them before running the agents again.

The vulnerability originates from a filename value derived from an OpenAPI or Swagger document. Affected agent definitions use this value in a shell operation without sufficient validation and quoting, allowing specially crafted input to change how the shell interprets the operation.

The vulnerability description identifies shell-based temporary-file cleanup instructions as the affected execution path. An attacker can supply a document containing shell metacharacters within the filename value.

When a developer invokes the vulnerable generator, those characters can cause the shell to execute attacker-controlled commands instead of treating the value only as a filename.

This makes document processing the attack entry point. The malicious content does not need to arrive as a standalone executable. Instead, an apparently ordinary API specification becomes dangerous when the affected agent passes document-derived data into a shell command.

Progress DataDirect GenAI Flaw

Successful exploitation can affect a developer workspace or a continuous integration environment where the agent runs. Progress warns that customers may observe unexpected files, commands, or other changes in these environments.

The vulnerability does not generate a specific product error message, meaning an obvious application warning cannot be relied upon to identify exploitation.

Progress identifies three affected files: ARCGenAI-Generator.agent.md version 2.0, ARCGenAI-Generator.prompt.md version 1.0, and ARCGenAI-EntityGen.agent.md version 1.0. These are agent and prompt definitions distributed through the project repository.

The corrected release updates all three definitions to version 2.1. Customers should check each file rather than assuming that replacing only the main generator definition addresses every affected component listed in the advisory.

Progress says the fix requires pulling the latest agent definitions from the repository. No installer, patch installation, or migration is required. The company strongly recommends completing this update before using the agents again.

Customers who previously processed untrusted or third-party OpenAPI or Swagger documents with affected definitions should review the associated workspace or CI environment for unexpected files and other signs of command execution.

This retrospective review is separate from updating the definitions because the advisory also addresses environments where potentially malicious documents were already processed. Customers with questions or concerns can open a Progress Technical Support case.

Stops threats before impact with 21 min faster MTTR. Integrate ANYRUN’s Sandbox in your SOC

The post Critical Progress DataDirect GenAI Flaw Lets Malicious OpenAPI Files Execute OS Commands appeared first on Cyber Security News.