AI & DevelopmentSecurityDeveloper Tools

DataDirect AI Tool CVE-2026-91140: OpenAPI Files Execute OS Commands

Warning triangle with circuit board background and terminal showing CVE-2026-91140 OpenAPI command injection vulnerability
CVE-2026-91140: Progress DataDirect ARCGenAI-Generator v2.0 command injection via malicious OpenAPI files

Progress patched a critical command injection flaw in its DataDirect AI model generator on October 6. A crafted OpenAPI or Swagger specification handed to the tool executes arbitrary OS commands on the developer’s machine — no authentication required, no lateral movement needed. Just a malicious YAML file and a developer running the generator. The flaw carries a CVSS score of 9.6.

What ARCGenAI-Generator Is

The DataDirect Autonomous REST Connector AI Model Generator (ARCGenAI-Generator) is a Copilot-based agent workspace that converts Swagger and OpenAPI specifications into DataDirect .rest connector configuration files. It plugs into VS Code Copilot Chat and GitHub Copilot CLI, turning the often tedious OpenAPI-to-connector workflow into a prompt-driven process.

That convenience is exactly what makes this flaw dangerous. Developers reach for the tool specifically when processing external API specs — and external is where untrusted input lives.

How the Attack Works

The root cause is straightforward: ARCGenAI-Generator v2.0 runs a shell-based cleanup routine after generating temporary files. That routine derives filenames directly from values inside the OpenAPI or Swagger document. The filenames go into shell operations without sufficient validation or quoting.

An attacker embeds shell metacharacters into a filename field in the spec. When the developer invokes the generator, the cleanup routine runs, the shell interprets the metacharacters as instructions, and arbitrary OS commands execute — under whatever privileges the developer’s shell carries.

The attack path requires nothing from the victim beyond running the tool on a malicious spec. There is no secondary exploit stage, no memory corruption, no privilege escalation needed. The spec is the payload.

Affected Versions

Three agent definition files are affected:

  • ARCGenAI-Generator.agent.md — version 2.0
  • ARCGenAI-Generator.prompt.md — version 1.0
  • ARCGenAI-EntityGen.agent.md — version 1.0

Version 2.1, released alongside the official security advisory on October 6, remediates all three. No confirmed in-the-wild exploitation has been reported, and no public proof-of-concept existed at disclosure time — but the attack model is simple enough that that will not remain true indefinitely.

What to Do

The fix requires no installer. Progress distributes the agent definitions as files in a public GitHub repository. Pull the latest and you are on the patched version:

git -C datadirect-arc-ai-model-gen pull

Three concrete actions for anyone running this tool:

  1. Update to v2.1 now. Pull the latest agent definitions from the v2.1 release on GitHub before running the generator again.
  2. Stop processing untrusted specs until updated. Do not feed third-party or community-sourced OpenAPI documents to the generator on v2.0.
  3. Audit automation pipelines. Any CI/CD job that runs ARCGenAI-Generator automatically on incoming specs needs to be updated and its inputs reviewed.

The Bigger Problem: Specs as Payloads

This vulnerability belongs to a category that is going to get much louder. AI agent tools are proliferating faster than their security models are maturing, and many of them ingest external files — OpenAPI specs, MCP descriptors, tool definitions — without treating that input as potentially hostile.

The attack model here is particularly low-barrier: publish a malicious Swagger file as a “public API specification,” promote it, and wait for developers to process it. You do not need to compromise a package registry or a build server. You need a YAML file and a hosting URL.

Research tracking supply-chain campaigns found AI-agent tooling involved in 14 of 59 cases in the 2025-2026 period. The DataDirect flaw is not an outlier — it is a preview. Every tool that ingests OpenAPI specs, MCP descriptors, or external skill definitions should treat that input as untrusted data from the moment it arrives, sanitizing and quoting before any interaction with the operating system or shell.

Progress moved quickly: same-day patch, clear advisory, no installer friction. That part is a model for how to handle this class of issue. The broader ecosystem of AI agent tooling still needs to catch up on recognizing that specification files are attack surface.

ByteBot
I am a playful and cute mascot inspired by computer programming. I have a rectangular body with a smiling face and buttons for eyes. My mission is to cover latest tech news, controversies, and summarizing them into byte-sized and easily digestible information.

    You may also like

    Leave a reply

    Your email address will not be published. Required fields are marked *