Progress DataDirect GenAI Bug Lets OpenAPI Files Run OS Commands

Progress DataDirect has disclosed a severe vulnerability in its GenAI agent definition system—specifically, a command injection flaw that could be abused via malicious OpenAPI or Swagger files. Identified as CVE-2026-91140, this issue affects the DataDirect Autonomous REST Connector AI Model Generator and enables untrusted document input to execute arbitrary operating system commands. The vulnerability was revealed in a security bulletin published on October 6, 2026. Users of the Early Access definitions from the public repository are urged to update immediately.

This bug stems from the way certain definitions extract a filename value from a provided OpenAPI or Swagger spec without properly sanitizing or quoting it. The affected definitions then use that filename in shell-based operations—such as temporary file cleanups—allowing specially crafted filenames loaded with shell metacharacters to mislead the shell into running attacker-specified commands instead of treating the filename as inert text.

What’s Affected & What’s Patched

The flaw compromises environments where developers use the outdated agent files: ARCGenAI-Generator.agent.mdversion 2.0, ARCGenAI-Generator.prompt.mdversion 1.0, and ARCGenAI-EntityGen.agent.mdversion 1.0. The updated definitions, now version 2.1 for all three, remediate the issue. Users should pull the latest versions—not assume that applying a patch to just one file will resolve all exposure.

No installer or complex migration is necessary to deploy the fix—simply updating the agent definitions from the repository suffices. It’s advised to complete this before running agents again. Moreover, if you’ve already processed documents from unknown or untrusted sources under vulnerable versions, you should audit your workspace or CI environments for signs of arbitrary file creation, unexpected commands, or other anomalies.

The vulnerability creates a particularly dangerous scenario because it can be triggered by basically any OpenAPI or Swagger document—even ones that appear innocuous. The agent’s mechanism for cleaning up or handling temporary files provides an unguarded gateway into OS-level access when filenames are not safely constrained.

Why It Matters

Artifacts like agent definitions are foundational to GenAI systems’ behavior—defining prompts, entities, and generation logic. When those foundations are compromised, the scale of possible damage grows fast. In this case, a developer environment or CI pipeline could be quietly subverted through any component that handles external API specs. The stealthy nature of the flaw—no obvious error messages or front-end warnings—makes detection hard without proactive auditing.

For organizations working with AI agents, this is a red flag: supply-chain style vulnerabilities in AI definitions or modules can become attack vectors. Ensuring that every part of a code or model-definition pipeline is trusted, validated, and updated is now clearly nonnegotiable.

What to Do:Immediately fetch the fixed definitions (version 2.1) from the public repository, replace the vulnerable files, and review any past document-processing activity for suspicious files or behavior. If in doubt, engage technical support.

Analysis:This incident highlights how AI and automation tools can magnify traditional software vulnerabilities—here, command injection—when they interact with external specifications. The gap between document parsing and system execution is now a critical security boundary. As GenAI agents proliferate, lessons from this vulnerability should push vendors toward stricter input validation, clearer ownership of agent definitions, and more robust automation pipelines. For users, staying ahead of updates, limiting externally sourced specs, and auditing agent behavior aren’t just best practices—they’re essential defense.