Threat reportVulnerabilityTL-2026-3226
Progress DataDirect GenAI Command Injection via OpenAPI/Swagger Filename (CVE-2026-91140)
Progress DataDirect GenAI Command Injection via (TL-2026-3226), also tracked as ARCGenAI command injection, is a critical-severity software vulnerability scored CVSS 9.6, first published 2026-10-10. It has no confirmed attribution, affects Progress Software DataDirect Autonomous REST Connector GenAI Agents, references 1 CVE (CVE-2026-91140), maps to 6 MITRE ATT&CK techniques (T1005, T1059.004, T1195), and is covered by 9 detection rules and 12 indicators of compromise.
- CVSS
- 9.6/10Critical
- CVEs
- 1Referenced vulnerabilities
- Techniques
- 6MITRE ATT&CK
- Actors
- 0Not attributed
- Detection rules
- 9SPL · KQL · Sigma
- IOCs
- 12Indicators of compromise
Key facts for TL-2026-3226
- Threat ID
- TL-2026-3226
- Also known as
- ARCGenAI command injection, DataDirect ARC AI Model Generator OS command injection
- Severity
- CRITICAL
- CVSS
- 9.6 (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H)
- Status
- ACTIVE
- Category
- VULNERABILITY
- First published
- Last reviewed
- Attribution confidence
- LOW
- Motivation
- UNKNOWN
- Target sectors
- technology, software-development
- Target regions
- Global
- Detection rules
- 9
- Indicators of compromise
- 12
Malware and tooling in Progress DataDirect GenAI Command Injection via
Malware and tooling: GitHub Copilot CLI, VS Code Copilot Chat
How Progress DataDirect GenAI Command Injection via works
CVE-2026-91140 is a critical (CVSS 9.6) OS command injection in the Progress DataDirect Autonomous REST Connector GenAI agent definitions (ARCGenAI-Generator.agent.md v2.0, ARCGenAI-Generator.prompt.md v1.0, ARCGenAI-EntityGen.agent.md v1.0). A filename derived from a crafted OpenAPI/Swagger document reaches a shell operation without validation or quoting, so shell metacharacters execute arbitrary commands. Version 2.1 of each definition fixes it. No in-the-wild exploitation or public PoC has been reported.
Progress publishes AI agent and prompt definition files in the progress/datadirect-arc-ai-model-gen GitHub repository. They drive an AI-assisted workflow, run through VS Code Copilot Chat and GitHub Copilot CLI, that converts OpenAPI/Swagger specifications into DataDirect Autonomous REST Connector (.rest) configuration files. The affected definitions are ARCGenAI-Generator.agent.md v2.0, ARCGenAI-Generator.prompt.md v1.0 and ARCGenAI-EntityGen.agent.md v1.0.
Root cause (CWE-78): a filename value derived from an OpenAPI/Swagger document was used in a shell operation without sufficient validation and quoting. Per the NVD-derived description the vulnerable logic sits in the shell-based temporary-file cleanup instructions. An attacker who can get a crafted Swagger/OpenAPI document processed can embed shell metacharacters in the filename-derived value. The shell then interprets those characters as commands when a user invokes the generator, which gives arbitrary OS command execution in the context of the user running the agent.
Impact is scoped to developer workspaces and CI environments that process untrusted API specifications with the vulnerable definitions. These hosts typically hold source code and credentials. The published CVSS 3.1 vector (AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H, score 9.6) reflects user-triggered invocation of the generator. One secondary report states no user interaction is required, and the sources disagree on this point. The NVD/OpenCVE record lists UI:R.
Remediation requires no installer or patch. Defenders pull the updated v2.1 definitions from the vendor GitHub repository; the fix (commit 7ede6d96eb033d647ffdcabf8d8069c098293575) adds filename quoting and validation safeguards. Environments that previously processed untrusted specs with vulnerable versions should be inspected for evidence of command execution. As of 2026-10-10 the CVE is not in the CISA KEV catalog, no public PoC has been identified, no exploitation has been reported, and the reported EPSS 30-day probability is 1.9%. No threat actor attribution exists and no network IOCs have been published, so no BeaconBeagle correlation was applicable.
MITRE ATT&CK techniques used in TL-2026-3226
Collection
Execution
T1059.004 Command and Scripting Interpreter: Unix Shell; T1203 Exploitation for Client Execution; T1204.002 User Execution: Malicious File
Initial Access
Credential Access
Affected products and versions in Progress DataDirect GenAI Command Injection via
- Progress Software — DataDirect Autonomous REST Connector GenAI Agents (ARCGenAI-Generator.agent.md)
Vulnerable versions: 2.0
Fixed in: 2.1 - Progress Software — DataDirect Autonomous REST Connector GenAI Agents (ARCGenAI-Generator.prompt.md)
Vulnerable versions: 1.0
Fixed in: 2.1 - Progress Software — DataDirect Autonomous REST Connector GenAI Agents (ARCGenAI-EntityGen.agent.md)
Vulnerable versions: 1.0
Fixed in: 2.1
Remediation for Progress DataDirect GenAI Command Injection via
Patches
- Progress DataDirect Autonomous REST Connector GenAI agent definitions v2.1 (fix commit 7ede6d96eb033d647ffdcabf8d8069c098293575)
Immediate actions
- Update ARCGenAI-Generator.agent.md, ARCGenAI-Generator.prompt.md and ARCGenAI-EntityGen.agent.md to v2.1 from the progress/datadirect-arc-ai-model-gen GitHub repository
- Do not process untrusted Swagger/OpenAPI documents with versions prior to 2.1
- Review developer workspaces and CI environments that processed untrusted specs with vulnerable definitions for evidence of command execution
Workarounds
- Avoid running the generator on untrusted OpenAPI/Swagger documents until upgraded
Longer-term hardening
- Treat third-party OpenAPI/Swagger specifications as untrusted input in AI-assisted developer and CI workflows
- Run AI agent tooling in isolated environments with least-privilege credentials
- Monitor shell child processes spawned by Copilot CLI and VS Code agent sessions
CVEs associated with Progress DataDirect GenAI Command Injection via
CVE-2026-91140
Weaknesses (CWE) in Progress DataDirect GenAI Command Injection via
Timeline of Progress DataDirect GenAI Command Injection via
- Fix commit 7ede6d96eb033d647ffdcabf8d8069c098293575 in progress/datadirect-arc-ai-model-gen adds filename quoting and validation safeguards (commit referenced by the CVE record on 2026-10-06; exact commit time not stated in sources)
- CVE-2026-91140 published with CVSS 3.1 score 9.6 (CRITICAL) and CWE-78
- Progress publishes its DataDirect critical security alert bulletin for CVE-2026-91140 and releases v2.1 of the affected agent definitions
- GBHackers, SecurityOnline and other outlets report the flaw; sources note no confirmed in-the-wild exploitation, no public PoC and an EPSS 30-day score of 1.9%
- CVE record last updated; not listed in the CISA KEV catalog
- Threadlinqs research review: still no reported exploitation, public PoC, attribution or network IOCs in available sources
Sources cited for Progress DataDirect GenAI Command Injection via
- Critical Progress DataDirect GenAI Flaw Lets Attackers Execute Arbitrary OS Commands
- OpenCVE - CVE-2026-91140
- Progress DataDirect Critical Security Alert Bulletin - CVE-2026-91140
- Fix commit in progress/datadirect-arc-ai-model-gen
- progress/datadirect-arc-ai-model-gen repository
- Progress Patches Critical DataDirect ARCGenAI Command-Injection Flaw
- Progress DataDirect vulnerability CVE-2026-91140 (SecurityOnline)
- Canadian Centre for Cyber Security - Progress security advisory AV26-1005
Detection coverage for TL-2026-3226
As of 2026-10-10, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-3226 across Splunk SPL, Microsoft KQL and Sigma, covering 12 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.