CVE-2026-91140 PUBLISHED

OS command injection in Progress Software Autonomous REST Connector GenAI Agents

Assigner: ProgressSoftware
Reserved: 14.09.2026 Published: 06.10.2026 Updated: 06.10.2026

An OS command injection vulnerability in the shell-based temporary-file cleanup instructions in Progress Software Autonomous REST Connector GenAI Agents ARCGenAI-Generator version 2.0 allows an attacker who supplies a crafted Swagger/OpenAPI document to execute arbitrary commands on a developer's machine when a user invokes the generator.

Metrics

CVSS Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H
CVSS Score: 9.6

Product Status

Vendor Progress Software
Product Autonomous REST Connector GenAI Agents
Versions Default: unaffected
  • affected from 2.0 to 2.1 (excl.)

Workarounds

Upgrade ARCGenAI-Generator to version 2.1 or later. Until the upgrade is applied, do not process untrusted Swagger/OpenAPI documents.

Solutions

Upgrade ARCGenAI-Generator to version 2.1 or later. Until the upgrade is applied, do not process untrusted Swagger/OpenAPI documents.

Credits

  • Abhishek Nandkumar Bhaskar (Abhi-Hackz) finder

References

Problem Types

  • CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') CWE

Impacts

  • An attacker can execute arbitrary operating system commands with the privileges of the user running the agent.