CVE-2026-91140: OS command injection in Progress Software Autonomous REST Connector GenAI Agents
An OS command injection vulnerability in the shell-based temporary-file cleanup instructions in Progress Software Autonomous REST Connector GenAI Agents ARCGenAI-Generator version 2.0 allows an attacker who supplies a crafted Swagger/OpenAPI document to execute arbitrary commands on a developer's machine when a user invokes the generator.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Progress Software Autonomous REST Connector GenAI Agents ARCGenAI-Generatorto a version that resolves this vulnerability.Fixed in 2.1 - Compensating control
Until the upgrade is applied, do not process untrusted Swagger/OpenAPI documents.
Event History
Frequently Asked Questions
Which environments are exposed?
Developer machines are exposed when they run ARCGenAI-Generator version 2.0 and invoke the generator using a Swagger/OpenAPI document supplied by an attacker.
Does an attacker need an account or other privileges on the developer's machine?
No attacker privileges are required according to the CVSS vector. The attacker needs to provide a crafted Swagger/OpenAPI document, and a user must invoke the generator with it.