Progress DataDirect Identifies Serious Security Vulnerability in AI Model Generator Agents
Progress has revealed a significant command injection vulnerability that affects the Early Access Release of its DataDirect Autonomous REST Connector AI Model Generator agents. This critical issue, designated as CVE-2026-91140, enables maliciously crafted OpenAPI or Swagger documents to execute arbitrary operating system commands on systems running the compromised agents.
According to a security bulletin issued on October 6, 2026, this vulnerability poses a serious risk as it allows attackers to exploit affected systems by manipulating the way certain documents are processed. These specially crafted documents can contain shell metacharacters that alter the interpretation of commands by the shell, potentially allowing the execution of attacker-controlled commands instead of solely treating the derived value as a filename.
How the Vulnerability Works
The security bulletin elaborates that the vulnerability arises from a filename parameter sourced from either OpenAPI or Swagger documentation. Unfortunately, affected agent definitions utilize this parameter in a shell operation without implementing adequate validation or quoting measures. This lack of safety allows an attacker to craft a document that could directly manipulate the environment in which the affected agents operate.
Importantly, the risk of exploitation exists wherever an affected agent is processing a malicious document. This could be within a developer workspace or a continuous integration environment, effectively limiting the impact to systems involved in generating connector models. The bulletin also notes that the repository includes a Copilot-based workflow, which facilitates the conversion of Swagger and OpenAPI specifications into .rest configuration files for DataDirect Autonomous REST Connector. This workflow is supported by popular tools like VS Code Copilot Chat and GitHub Copilot CLI, which are followed by manual review, validation, and launch steps.
Specific Affected Components and Available Fixes
Progress has identified three specific components that are currently affected by this vulnerability:
- ARCGenAI-Generator.agent.md, version 2.0
- ARCGenAI-Generator.prompt.md, version 1.0
- ARCGenAI-EntityGen.agent.md, version 1.0
To mitigate the risks linked to CVE-2026-91140, it is essential for users to update to version 2.1 of each affected definition. Progress has made it clear that the remediation involves simply retrieving the latest agent definitions from the public GitHub repository and that no installations, patches, or migrations are required.
It is worth noting that the EntityGen component serves as an internal sub-agent that is automatically invoked by the Generator. As such, merely reviewing the top-level generation definition could result in overlooking the EntityGen component, which is also included in the list of affected versions. Users are advised not to invoke the EntityGen sub-agent directly, as this may inadvertently expose the system to further risks.
Symptoms of Exploitation and Recommendations
The bulletin stresses that this vulnerability does not trigger explicit error messages within the product itself. Customers utilizing the compromised definitions may observe unexpected files, commands, or unplanned changes in the workspace or CI environment after a crafted document has been processed by an affected agent.
In light of this vulnerability, customers who have previously utilized vulnerable definitions in conjunction with untrusted or third-party specifications should conduct thorough inspections of their environments to detect any unusual files or indications of command execution. Current documentation from the repository emphasizes the importance of treating input values from Swagger and OpenAPI fields as untrusted, rather than as executable instructions. The Generator is designed to pause for clarification when filename derivation includes unsafe path-like characters.
The bulletin, however, does not include a CVSS (Common Vulnerability Scoring System) score, statistics regarding exploitation, or evidence of active attacks leveraging this vulnerability. Priority for users is to update all three affected definitions before proceeding with any further generation tasks.
Conclusion
In conclusion, Progress DataDirect’s announcement about the significant command injection vulnerability serves as a critical reminder of the importance of maintaining software security. As organizations increasingly rely on AI models and automation, ensuring the integrity of these systems must remain a top priority. The immediate recommendation is for users to swiftly update their definitions, thus safeguarding their environments against potential exploits that may arise from this vulnerability.

