CVE-2026-91140

Summary

An OS command injection vulnerability in the shell-based temporary-file cleanup instructions in Progress Software Autonomous REST Connector GenAI Agents ARCGenAI-Generator version 2.0 allows an attacker who supplies a crafted Swagger/OpenAPI document to execute arbitrary commands on a developer's machine when a user invokes the generator.

Affected Software

VendorProductVersion RangeStatus
Progress SoftwareAutonomous REST Connector GenAI Agents2.0 < 2.1affected

Weaknesses

  • CWE-78: CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')

Workarounds

Upgrade ARCGenAI-Generator to version 2.1 or later. Until the upgrade is applied, do not process untrusted Swagger/OpenAPI documents.

ADP Enrichment

CISA ADP Vulnrichment

  • SSVC:
  • Exploitation: none
    • Automatable: no
    • Technical Impact: total

References