{"id":"CVE-2026-91140","title":"An OS command injection vulnerability in the shell-based temporary-file cleanup instructions in Progress Software Autonomous REST Connector GenAI Agents ARCGenAI-Generator version 2.0 allows an attacker who supplies a crafted Swagger/Ope…","summary":"An OS command injection vulnerability in the shell-based temporary-file cleanup instructions in Progress Software Autonomous REST Connector GenAI Agents ARCGenAI-Generator version 2.0 allows an attacker who supplies a crafted Swagger/Ope…","severity":"critical","cvss":9.6,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H","cwe":["CWE-78"],"vendor":"Progress Software","product":"Autonomous REST Connector GenAI Agents","affected":["autonomous_rest_connector_genai_agents >= 2.0 < 2.1"],"published":"2026-10-06","updated":"2026-10-06","sourceUpdated":"2026-10-06T15:09:20.387","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-91140","references":[{"url":"https://community.progress.com/s/article/Progress-DataDirect-Critical-Security-Alert-Bulletin-September-2026-CVE-2026-91140","label":"security@progress.com"},{"url":"https://github.com/progress/datadirect-arc-ai-model-gen/commit/7ede6d96eb033d647ffdcabf8d8069c098293575","label":"security@progress.com"}],"tags":["nvd","cve.org"],"ssvc":{"exploitation":"none","automatable":"no","technicalImpact":"total","timestamp":"2026-10-06T14:03:23.002600Z"},"ingestedAt":"2026-10-06T14:00:19.139Z","slug":"CVE-2026-91140","body":"## Overview\n\nAn OS command injection vulnerability in the shell-based temporary-file cleanup instructions in Progress Software Autonomous REST Connector GenAI Agents ARCGenAI-Generator version 2.0 allows an attacker who supplies a crafted Swagger/OpenAPI document to execute arbitrary commands on a developer's machine when a user invokes the generator.\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.","depth":"midnight","depthScore":53,"depthScoreParts":{"impact":52.8,"likelihood":0,"exploitation":0,"ransomware":0},"changes":[]}