Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
Critical Flaw in Progress DataDirect GenAI Exposes Systems

Critical Flaw in Progress DataDirect GenAI Exposes Systems

Posted on October 7, 2026 By CWS

Progress has announced a critical security vulnerability identified as CVE-2026-91140 in its DataDirect Autonomous REST Connector AI Model Generator. This flaw allows malicious OpenAPI or Swagger files to execute arbitrary operating system commands.

Details of the Vulnerability

On October 6, 2026, Progress released a security bulletin detailing the vulnerability, which affects Early Access agent definitions available via the public progress/datadirect-arc-ai-model-gen GitHub repository. It is crucial for users to update these definitions before using the agents again.

The flaw stems from a filename value extracted from OpenAPI or Swagger documents, which is utilized in shell operations without adequate validation or quoting. This oversight can permit specially crafted input to alter shell command interpretations, leading to execution of attacker-controlled commands.

Impact and Mitigation Measures

The vulnerability primarily exploits shell-based temporary-file cleanup instructions, creating potential attack vectors within developer workspaces or continuous integration environments. Progress emphasizes that the malicious input does not need to be a standalone executable, but rather an API specification that becomes hazardous when processed by the affected agent.

Notably, the flaw does not trigger a specific error message, making detection challenging without careful monitoring. Developers might observe unexpected files or commands as a sign of exploitation.

Recommended Actions for Users

Progress has identified three agent and prompt definitions affected by this vulnerability: ARCGenAI-Generator.agent.md version 2.0, ARCGenAI-Generator.prompt.md version 1.0, and ARCGenAI-EntityGen.agent.md version 1.0. The company has released updated versions 2.1 for all definitions, and users are advised to obtain these from the repository immediately.

Customers who have previously processed untrusted OpenAPI or Swagger documents with the vulnerable definitions should thoroughly review their workspaces or CI environments for unexpected changes. This proactive review is crucial even after updating the definitions, as it addresses environments where potentially harmful documents might have already been executed.

For further assistance, customers are encouraged to contact Progress Technical Support. Implementing these updates and reviews can significantly mitigate the risks posed by this critical flaw.

Cyber Security News Tags:agent definitions, CI environments, command injection, Cybersecurity, DataDirect, GenAI, OpenAPI, Progress, Security, shell commands, software update, Swagger, technical support, Vulnerability

Post navigation

Previous Post: Georgia Power, Alabama Power Data Breach Affects 400,000
Next Post: Understanding Agentic Pentesting: Benefits and Boundaries

Related Posts

GoBruteforcer Botnet Attacking Linux Servers Worldwide GoBruteforcer Botnet Attacking Linux Servers Worldwide Cyber Security News
Splunk Universal Forwarder on Windows Lets Non-Admin Users Access All Contents Splunk Universal Forwarder on Windows Lets Non-Admin Users Access All Contents Cyber Security News
Microsoft Confirms August 2025 Update Causes Severe Lag in Windows 11 24H2, Windows 10 Versions Microsoft Confirms August 2025 Update Causes Severe Lag in Windows 11 24H2, Windows 10 Versions Cyber Security News
APT MuddyWater Attacking CFOs Leveraging OpenSSH, Enables RDP, and Scheduled Task APT MuddyWater Attacking CFOs Leveraging OpenSSH, Enables RDP, and Scheduled Task Cyber Security News
Jenkins Security Flaws Pose Major XSS Threats Jenkins Security Flaws Pose Major XSS Threats Cyber Security News
Microsoft Scripting Engine 0-Day Vulnerability Enables Remote Code Execution Over Network Microsoft Scripting Engine 0-Day Vulnerability Enables Remote Code Execution Over Network Cyber Security News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • AI-Driven Cyber Attacks by CyberXero Target Global Sites
  • Qilin Ransomware Member Extradited from Japan to Germany
  • Understanding Agentic Pentesting: Benefits and Boundaries
  • Critical Flaw in Progress DataDirect GenAI Exposes Systems
  • Georgia Power, Alabama Power Data Breach Affects 400,000

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • October 2026
  • September 2026
  • August 2026
  • July 2026
  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • AI-Driven Cyber Attacks by CyberXero Target Global Sites
  • Qilin Ransomware Member Extradited from Japan to Germany
  • Understanding Agentic Pentesting: Benefits and Boundaries
  • Critical Flaw in Progress DataDirect GenAI Exposes Systems
  • Georgia Power, Alabama Power Data Breach Affects 400,000

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark