CVE-2026-91140

LOWCVSS 9.6 · CRITICAL

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

An OS command injection vulnerability in the shell-based temporary-file cleanup instructions in Progress Software Autonomous REST Connector GenAI Agents ARCGenAI-Generator version 2.0 allows an attacker who supplies a crafted Swagger/OpenAPI document to execute arbitrary commands on a developer's machine when a user invokes the generator.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-78

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

STABLE

Threat summary

  • 2 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Peaked 1d ago at 1 mentions (2026-10-06); latest day: 1
  • 2 total mentions across 2 days

Deep dive

Activity timeline2 mentions / 2d
00111Mentions · 2026-10-06: 1Mentions · 2026-10-07: 110-0610-07
Referenced assets2 URLs
Full discourse2 posts
  • The Daily Tech Feed@dailytechonx

    Critical flaw discovered in Progress DataDirect’s GenAI agent definitions allows malicious OpenAPI or Swagger files to execute OS commands. CVE-2026-91140 lets attackers weaponize document filenames to trigger shell commands. Users should fetch the updated 2.1 definitions for all three affected components and audit any past use of untrusted specs. #Security #GenAI #Vulnerability #ProgressDataDirect #Security #GenAI #Vulnerability #ProgressDataDirect #CVE2026 #Cybersecurity https://thedailytechfeed.com/progress-datadirect-genai-bug-lets-openapi-files-run-os-commands/

    0000014
    783 followersView on X
  • Daily CyberSecurity@Daily_CyberSec

    Progress DataDirect vulnerability CVE-2026-91140 enables command injection via crafted OpenAPI files in AI agents. Pull version 2.1 now. #Progress #DataDirect #CVE202691140 #CommandInjection #AIAgents #OpenAPI #DevSecOps #Vulnerability https://securityonline.info/progress-datadirect-vulnerability-cve-2026-91140/

    00000358
    13.0K followersView on X

Explore more