Track vulnerabilities like this one.
Sign up free to get alerted when software you use is affected.
9.6
CVE-2026-91140: Progress Autonomous REST Connector can run unwanted commands
CVE-2026-91140 · published 4 days ago
Summary
The Autonomous REST Connector GenAI Agents version 2.0 can be tricked by a specially crafted API description file to run any command on the developer’s computer during generation. This could let an attacker take control of the machine or steal data. Update to a patched version or stop using untrusted API files until the fix is applied.
What to do
- Update progress software autonomous rest connector genai agents to version 2.1 or later.
Affected software
| Vendor | Product | Affected versions |
|---|---|---|
| progress software | autonomous rest connector genai agents | < 2.1 |
Original advisory text
OS command injection in Progress Software Autonomous REST Connector GenAI Agents
An OS command injection vulnerability in the shell-based temporary-file cleanup instructions in Progress Software Autonomous REST Connector GenAI Agents ARCGenAI-Generator version 2.0 allows an attacker who supplies a crafted Swagger/OpenAPI document to execute arbitrary commands on a developer's machine when a user invokes the generator.
References
- https://community.progress.com/s/article/Progress-DataDirect-Critical-Security-A...
- https://github.com/progress/datadirect-arc-ai-model-gen/commit/7ede6d96eb033d647...
- https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/91xxx/CVE-2026-91140... Vendor Advisory
- https://nvd.nist.gov/vuln/detail/CVE-2026-91140 Vendor Advisory
Internet-facing
14 days
Internal
At next upgrade
- Not known to be exploited
- Needs hands-on effort to exploit
- Gives an attacker full control
Type
CWE-78OS Command Injection
Timeline
Published6 Oct 2026
Updated9 Oct 2026
First seen6 Oct 2026
Track software like this
Free during beta