Progress disclosed a command-injection flaw in the early-access DataDirect Autonomous REST Connector AI Model Generator. CVE-2026-91140 lets a crafted OpenAPI or Swagger document execute operating system commands in the environment running the agent. The bulletin is dated 6 October 2026. Progress has not published a CVSS score and has not reported active exploitation.
What happened
The agent definitions take a filename value from the specification and pass it into a shell operation without enough validation or quoting. Shell metacharacters in that field are interpreted as commands, not as a file name. The workflow is a Copilot-based generator that turns Swagger and OpenAPI specs into Autonomous REST Connector configuration files, via VS Code Copilot Chat or GitHub Copilot CLI.
Three definition files are affected: ARCGenAI-Generator.agent.md 2.0, ARCGenAI-Generator.prompt.md 1.0, and ARCGenAI-EntityGen.agent.md 1.0. Version 2.1 of each definition is the fix. EntityGen is an internal sub-agent called by the generator, so updating only the top-level file is not enough. No installer is required. Replace the definition files from the vendor repository.
Who is affected
Developer workstations and CI jobs that ran the early-access generator against an OpenAPI or Swagger file, especially a file from a third party or an untrusted repo. The blast radius is the machine or pipeline that processed the document, not every DataDirect connector in production.
- Replace all three agent and prompt definitions with version 2.1
- Do not invoke the EntityGen sub-agent directly
- Treat specification fields as untrusted input, not as instructions
What to do now
Pull version 2.1 of all three definitions before anyone runs the generator again, including in CI. If an untrusted spec was already processed, inspect that workspace and pipeline for unexpected files and unexpected shell activity. Do not assume a quiet terminal means the run was clean.
Source: GBHackers, 7 October 2026, Critical Progress DataDirect GenAI flaw lets attackers execute arbitrary OS commands. Vendor bulletin: Progress security alert.
Also on the blog
- CVE-2026-21589: unauthenticated file read on Atlassian Data Center
- FortiBleed: FBI says 86,644 Fortinet device credentials still in play
- CVE-2026-102255: CVSS 10 SSRF in SonicWall SMA1000
- LunexStealer: 100-plus sites push fake Cloudflare checks
Next step: If this is on your network or a client's, ask Matthews Enterprises to check exposure.