TL;DR
Progress has fixed CVE-2026-91140, a critical Progress DataDirect vulnerability in its Autonomous REST Connector AI Model Generator agents. A crafted OpenAPI or Swagger file could run commands wherever the agents process it. Updated agent definitions, version 2.1, close the hole.
- CVE: CVE-2026-91140
- CVSS: 9.6 (Critical · CVSSv3)
- Product: Progress Software Autonomous REST Connector GenAI Agents
- Affected: 2.0
- Impact: OS command injection in Progress Software Autonomous REST Connector GenAI Agents
- Status: No confirmed exploitation yet
- Patched in: 2.1
- Action: Update to 2.1 now
CISA KEV isn't the only exploit signal. Pro/Team adds a second confirmed-exploit feed.
Try free for 14 daysWhy It Matters
The flaw sits in AI agent definitions, not a traditional installer. Developers pull these files from the public progress/datadirect-arc-ai-model-gen repository on GitHub. They run them in developer workspaces and CI pipelines, which often hold source code and secrets.
Progress labels the release “Early Access.” Even so, the bulletin calls the bug critical. Progress does not report exploitation in the wild, and no public proof-of-concept has been confirmed.
How the Attack Works
The agents read OpenAPI or Swagger documents to generate data models. According to Progress, “a filename value derived from an OpenAPI/Swagger document was used in a shell operation without sufficient validation and quoting.”
As a result, a crafted document “could introduce shell metacharacters and cause command execution.” Any team that feeds the agents an untrusted or third-party API spec faces the risk. In short, this is a classic command injection bug, but one triggered through an AI workflow.
Affected Versions
- ARCGenAI-Generator.agent.md version 2.0
- ARCGenAI-Generator.prompt.md version 1.0
- ARCGenAI-EntityGen.agent.md version 1.0
Patch and Mitigation Steps
Pull version 2.1 of all three agent definitions before running the agents again. Progress notes that “no installer, patch installation or migration is required.”
Next, check past runs. Progress warns that teams who processed untrusted specs “should review the associated workspace or CI environment for unexpected files or other signs of command execution.” Full guidance appears in the Progress DataDirect critical security alert bulletin. Treat this Progress DataDirect vulnerability as a reminder to vet any input that AI agents turn into shell commands.
Support Our Threat Intelligence
Find our vulnerability reports and weekly recaps helpful? Support our work today and unlock a 100% ad-free reading experience!