
Critical flaw discovered in Progress DataDirect’s GenAI agent definitions allows malicious OpenAPI or Swagger files to execute OS commands. CVE-2026-91140 lets attackers weaponize document filenames to trigger shell commands. Users should fetch the updated 2.1 definitions for all three affected components and audit any past use of untrusted specs. #Security #GenAI #Vulnerability #ProgressDataDirect #Security #GenAI #Vulnerability #ProgressDataDirect #CVE2026 #Cybersecurity https://thedailytechfeed.com/progress-datadirect-genai-bug-lets-openapi-files-run-os-commands/

