PROGRESS has addressed a critical command injection flaw in Progress DataDirect’s Autonomous REST Connector GenAI Agents, tracked as CVE-2026-91140. The issue centres on how AI model generator agents read OpenAPI or Swagger documents. A crafted, untrusted API specification could trigger a shell command through a filename value derived from the document, allowing OS command execution within the agent workflow.
Progress rates the vulnerability as critical with CVSS v3.0 at 9.6, though there are no confirmed exploitation reports to date. The fix is included in the fresh 2.1 update for the affected agent definitions.
The vulnerability affects the AI model generator components, specifically ARCGenAI-Generator.agent[.]md version 2.0, ARCGenAI-Generator.prompt[.]md version 1.0, and ARCGenAI-EntityGen.agent[.]md version 1.0. These definitions are loaded from the public progress/datadirect-arc-ai-model-gen repository and run in developers’ workspaces and CI pipelines. Progress notes that no installer or migration is required to deploy the patch; users should simply update to version 2.1 and re-run the agents.
In addition, teams are advised to inspect past runs and review their workspaces or CI environments for any signs of command execution or unexpected files resulting from processing untrusted specs.
Progress’ bulletin emphasises vetting input that AI agents convert into shell commands and recommends reviewing related environments for signs of compromise. While Progress reports no active exploitation in the wild, organisations using these agents should apply the 2.1 update promptly and monitor for any anomalous activity in CI or workspace histories.