CRITICAL 9.6 NVD
CVE-2026-91140
An OS command injection vulnerability in the shell-based temporary-file cleanup instructions in Progress Software Autonomous REST Connector GenAI Agents ARCGenA
An OS command injection vulnerability in the shell-based temporary-file cleanup instructions in Progress Software Autonomous REST Connector GenAI Agents ARCGenAI-Generator version 2.0 allows an attacker who supplies a crafted Swagger/OpenAPI document to execute arbitrary commands on a developer's machine when a user invokes the generator.
References
- https://community.progress.com/s/article/Progress-DataDirect-Critical-Security-Alert-Bulle
- https://github.com/progress/datadirect-arc-ai-model-gen/commit/7ede6d96eb033d647ffdcabf8d8
This critical severity vulnerability with a CVSS score of 9.6 was published on 2026-10-06 via NVD.
Risk Timeline
CVE Disclosed2026-10-06 · -1 days ago
Remediation Resources
vulnfeed aggregates 9311 vulnerabilities from NVD, CISA KEV,
Ubuntu, Debian, Red Hat, Kubernetes, Exploit-DB, OSS-Security, GitHub and OpenStack — updated every 4 hours.