Cyber Security News

Critical Progress DataDirect GenAI Flaw Lets Attackers Execute Arbitrary OS Commands

Progress has disclosed a critical command injection vulnerability in the Early Access Release of its DataDirect Autonomous REST Connector AI Model Generator agents.

This vulnerability, tracked as CVE-2026-91140, allows specially crafted OpenAPI or Swagger documents to execute arbitrary operating system commands within the environment running an affected agent.

The security bulletin, dated October 6, 2026, identifies the vulnerable agent and prompt definitions available through the public GitHub repository at progress/datadirect-arc-ai-model-gen. Progress has provided updated definitions and urges customers to download them before using the agents again.

Progress DataDirect GenAI Flaw

According to the bulletin, the vulnerability arises from a filename value taken from an OpenAPI or Swagger document. Affected agent definitions utilize this value in a shell operation without adequate validation and quoting.

An attacker could construct a document containing shell metacharacters that modify how the shell interprets the operation. Instead of treating the derived value purely as a filename, the shell may execute attacker-controlled commands.

Exploitation relies on an affected agent processing a malicious document, which could occur in a developer workspace or a continuous integration environment. This limits the impact to systems used to generate connector models.

The repository describes a Copilot-based workflow that converts Swagger and OpenAPI specifications into DataDirect Autonomous REST Connector .rest configuration files. This process supports generation through VS Code Copilot Chat and GitHub Copilot CLI, followed by manual review, validation, and launch steps.

Affected Definitions and Fixes

Progress lists three components that are affected:

  • ARCGenAI-Generator.agent.md, version 2.0
  • ARCGenAI-Generator.prompt.md, version 1.0
  • ARCGenAI-EntityGen.agent.md, version 1.0

Version 2.1 of each definition addresses this vulnerability. The remediation involves retrieving the latest agent definitions from the repository. Progress states that no installer, patch installation, or migration is required.

The EntityGen component is an internal sub-agent invoked automatically by the Generator. As a result, simply reviewing the top-level generation definition may overlook another component explicitly included in the vendor’s list of affected versions. The repository also warns users not to invoke the entity sub-agent directly.

This vulnerability does not trigger a specific product error message. Instead, customers may notice unexpected files, commands, or other changes in the workspace or CI environment where an affected agent processed a crafted document.

Customers who have previously utilized vulnerable definitions with untrusted or third-party specifications should inspect those environments for unexpected files and other signs of command execution.

Current repository documentation states that values from Swagger and OpenAPI fields must be treated as untrusted input, rather than executable instructions. It also mentions that the Generator will pause for clarification when filename derivation includes unsafe path-like characters.

The bulletin does not provide a CVSS score, exploitation statistics, or evidence of active attacks. Its immediate operational priority is to update all three definitions before running any further generation.

Stops Cyber threats before impact with 21 min faster MTTR. Integrate ANYRUN’s Sandbox in your SOC.

Divya

Divya is a Senior Journalist at GBhackers covering Cyber Attacks, Threats, Breaches, Vulnerabilities and other happenings in the cyber world.

Recent Posts

Insignary Launches Clarity AIR to Detect Undeclared Open-Source and AI-Written Code

Toronto, Canada, October 8th, 2026, CyberNewswire Insignary Launches Clarity AIR: Closing the Blind Spot Between…

20 minutes ago

Hackers Hijack Tensorlake Package to Spread Shai-Hulud Supply Chain Malware

A threat actor published a malicious version of the tensorlake npm package on October 8,…

2 hours ago

PoC Exploit Released for Zammad Vulnerability Enabling Session Hijacking and Remote Code Execution

A proof-of-concept (PoC) exploit has been released for CVE-2026-102489, a critical vulnerability in Zammad that…

2 hours ago

Critical LMCache RCE Vulnerability Remains Unpatched, Public PoC Exploit Available

A critical vulnerability in LMCache allows unauthenticated attackers to execute arbitrary code against reachable multi-process…

2 hours ago

16 Malicious Firefox Extensions Impersonate Crypto Wallets to Steal Seed Phrases and Private Keys

16 malicious Firefox extensions that impersonate cryptocurrency wallets to intercept recovery phrases and private keys…

3 hours ago

Exposed DarkSword iOS Servers Reveal Crypto Wallet Theft From Compromised iPhones

Exposed directories on five servers have revealed an operational DarkSword/Coruna exploitation platform built to compromise…

4 hours ago