Progress has disclosed a critical command injection vulnerability in the Early Access Release of its DataDirect Autonomous REST Connector AI Model Generator agents.
This vulnerability, tracked as CVE-2026-91140, allows specially crafted OpenAPI or Swagger documents to execute arbitrary operating system commands within the environment running an affected agent.
The security bulletin, dated October 6, 2026, identifies the vulnerable agent and prompt definitions available through the public GitHub repository at progress/datadirect-arc-ai-model-gen. Progress has provided updated definitions and urges customers to download them before using the agents again.
Progress DataDirect GenAI Flaw
According to the bulletin, the vulnerability arises from a filename value taken from an OpenAPI or Swagger document. Affected agent definitions utilize this value in a shell operation without adequate validation and quoting.
An attacker could construct a document containing shell metacharacters that modify how the shell interprets the operation. Instead of treating the derived value purely as a filename, the shell may execute attacker-controlled commands.
Exploitation relies on an affected agent processing a malicious document, which could occur in a developer workspace or a continuous integration environment. This limits the impact to systems used to generate connector models.
The repository describes a Copilot-based workflow that converts Swagger and OpenAPI specifications into DataDirect Autonomous REST Connector .rest configuration files. This process supports generation through VS Code Copilot Chat and GitHub Copilot CLI, followed by manual review, validation, and launch steps.
Affected Definitions and Fixes
Progress lists three components that are affected:
- ARCGenAI-Generator.agent.md, version 2.0
- ARCGenAI-Generator.prompt.md, version 1.0
- ARCGenAI-EntityGen.agent.md, version 1.0
Version 2.1 of each definition addresses this vulnerability. The remediation involves retrieving the latest agent definitions from the repository. Progress states that no installer, patch installation, or migration is required.
The EntityGen component is an internal sub-agent invoked automatically by the Generator. As a result, simply reviewing the top-level generation definition may overlook another component explicitly included in the vendor’s list of affected versions. The repository also warns users not to invoke the entity sub-agent directly.
This vulnerability does not trigger a specific product error message. Instead, customers may notice unexpected files, commands, or other changes in the workspace or CI environment where an affected agent processed a crafted document.
Customers who have previously utilized vulnerable definitions with untrusted or third-party specifications should inspect those environments for unexpected files and other signs of command execution.
Current repository documentation states that values from Swagger and OpenAPI fields must be treated as untrusted input, rather than executable instructions. It also mentions that the Generator will pause for clarification when filename derivation includes unsafe path-like characters.
The bulletin does not provide a CVSS score, exploitation statistics, or evidence of active attacks. Its immediate operational priority is to update all three definitions before running any further generation.
Stops Cyber threats before impact with 21 min faster MTTR. Integrate ANYRUN’s Sandbox in your SOC.

