The Spec Is the Shell: Progress’s 9.6 ARCGenAI Command Injection via OpenAPI Filenames

Progress Software’s September 2026 critical security bulletin for DataDirect carries an entry purpose-built for this site’s beat: CVE-2026-91140, a CVSS 3.1 9.6 OS command injection in the company’s Autonomous REST Connector GenAI agents, published to NVD on 6 October 2026. An attacker who supplies a crafted Swagger or OpenAPI document gets arbitrary command execution on the developer’s machine when the victim invokes the generator. The weapon is not a prompt. It is a filename.

NVD’s description, filed by Progress as CNA, is admirably concrete: “An OS command injection vulnerability in the shell-based temporary-file cleanup instructions in Progress Software Autonomous REST Connector GenAI Agents ARCGenAI-Generator version 2.0.” Progress’s own account, quoted in secondary coverage of the bulletin, names the defect precisely: “a filename value derived from an OpenAPI/Swagger document was used in a shell operation without sufficient validation and quoting,” so that a crafted document “could introduce shell metacharacters and cause command execution.” Somewhere in the agent’s temp-file cleanup, a value the attacker controls met a shell unquoted. That is the entire vulnerability, and it is enough for 9.6.

Why the vector scores the way it does

The vector is CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H — network attack vector, low complexity, no privileges required, user interaction required, changed scope, full confidentiality, integrity and availability impact. Decode it: anyone who can get a malicious API spec in front of the generator needs nothing else — no account, no prior access. The “user interaction” is the victim doing their job: pointing the agent at a spec. The scope change reflects that the compromise lands beyond the vulnerable component, on the developer’s machine itself. Classified CWE-78 (OS command injection), which is exactly what it is — no exotic agent semantics required.

The affected artifacts are agent definitions, not binaries: ARCGenAI-Generator.agent.md version 2.0, alongside ARCGenAI-Generator.prompt.md 1.0 and ARCGenAI-EntityGen.agent.md 1.0, all pulled from Progress’s public progress/datadirect-arc-ai-model-gen repository and run in developer workspaces and CI pipelines — environments that hold source code and secrets. The fix is version 2.1 of all three definitions, and Progress notes that “no installer, patch installation or migration is required.” You pull new markdown files. That frictionlessness cuts both ways: updating is trivial, but so is running the vulnerable version, which looks like documentation rather than software and will not trip any patch-management process watching installers.

The fix shipped a month before the CVE

The NVD record references the fix commit directly, and the commit tells its own story. The remediation — merge of pull request #2, “XDBC-77958 quote shell file name vars” — landed in the public repository on 10 September 2026. The bulletin followed later in September; the CVE record was published 6 October. So the patch sat in a public repo for nearly a month before the identifier existed, and the identifier arrived a month after the code was fixed.

Readers will recognise the pattern. We documented it twice in the past week: Dell’s DSU advisory published 65 days after the fixed build shipped as “Optional”, and Microsoft’s Exchange V2 update that reached servers before its own advisory. Here it is a third time, in miniature: the engineering outran the communication, and anyone diffing the September commits had a head start on defenders waiting for an identifier. To be fair to Progress, the exposure here requires the victim to process a hostile spec — it is not a wormable service flaw — but the sequencing still meant the most security-conscious consumers, the ones who wait for a CVE before acting, were the last to know.

The threat model this belongs to

This is the same class we keep finding at the agent boundary: untrusted input promoted into a trusted execution context. The generator reads a third-party API description — exactly the kind of file developers routinely download from vendors, partners, and forums — and a derived string reaches a shell. It does not require prompt injection, model compromise, or any “AI” attack at all. A conventional code generator with the same cleanup routine would have the same CVE. The agent framing matters for one reason only: these definition files run with the developer’s permissions, in workspaces full of credentials, and they are shared and forked like any other AI-agent artifact, without the signing, versioning discipline, or patch tooling that surrounds real packages.

Note what the bulletin does not claim. Progress reports no exploitation in the wild, no public proof of concept has been confirmed, and we verified CVE-2026-91140 is absent from CISA’s KEV catalog. The NVD record sits at “Awaiting Analysis.” That is the normal posture for a six-day-old CVE, not a clean bill of health — and the one-line fix in a public repo means any competent reader can reconstruct the exploit from the diff.

What to do

  • Pull agent-definition version 2.1 before running the generator again. All three files, not just the generator — Progress ships the set together. There is no installer to run, which also means nothing will prompt you.
  • Audit past runs against untrusted specs. Progress explicitly warns teams that processed untrusted specifications to “review the associated workspace or CI environment for unexpected files or other signs of command execution.” Treat any third-party or forum-sourced spec you fed the 2.0 generator as a potential compromise of that workspace.
  • Inventory your agent-definition files like dependencies. If a markdown file can execute shell commands with your credentials, it belongs in version control with pinned versions and change review — not pasted from a repo into a working directory.
  • Quarantine third-party specs by default. Vendor and partner OpenAPI documents are untrusted input until proven otherwise. Fetch them, inspect them, and never let a generator process one straight from a URL you did not choose.
  • Watch the shell boundary in your own agents. If you build agents that shell out, quote and validate every derived value — filenames especially. The Progress fix was literally quoting shell filename variables. Audit yours before someone else’s bulletin names them.

Verification note: the CVE identifier, NVD description, CVSS 3.1 score (9.6), vector string, CWE-78 classification, CNA source (security@progress.com), publication timestamp (6 October 2026), “Awaiting Analysis” status and both reference URLs were read directly from the NVD API record for CVE-2026-91140 on 7 October 2026. The fix-commit message, PR number, internal ticket reference and 10 September 2026 commit date were read from the GitHub API record for the referenced commit. The quoted Progress bulletin passages, affected file versions, 2.1 remediation, “no installer” note, Early Access label and no-exploitation/no-PoC status come via SecurityOnline’s 6 October 2026 report quoting the Progress bulletin, which we could not render directly (Salesforce community page requires JavaScript). KEV absence verified against CISA’s catalog file dated 4 October 2026. We assert no exploitation activity and no technical mechanism beyond what these sources state.

Sources: