Threat reportVulnerabilityTL-2026-3226

Progress DataDirect GenAI Command Injection via OpenAPI/Swagger Filename (CVE-2026-91140)

criticalACTIVE

Progress DataDirect GenAI Command Injection via (TL-2026-3226), also tracked as ARCGenAI command injection, is a critical-severity software vulnerability scored CVSS 9.6, first published 2026-10-10. It has no confirmed attribution, affects Progress Software DataDirect Autonomous REST Connector GenAI Agents, references 1 CVE (CVE-2026-91140), maps to 6 MITRE ATT&CK techniques (T1005, T1059.004, T1195), and is covered by 9 detection rules and 12 indicators of compromise.

CVSS
9.6/10Critical
CVEs
1Referenced vulnerabilities
Techniques
6MITRE ATT&CK
Actors
0Not attributed
Detection rules
9SPL · KQL · Sigma
IOCs
12Indicators of compromise

Key facts for TL-2026-3226

Threat ID
TL-2026-3226
Also known as
ARCGenAI command injection, DataDirect ARC AI Model Generator OS command injection
Severity
CRITICAL
CVSS
9.6 (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H)
Status
ACTIVE
Category
VULNERABILITY
First published
Last reviewed
Attribution confidence
LOW
Motivation
UNKNOWN
Target sectors
technology, software-development
Target regions
Global
Detection rules
9
Indicators of compromise
12

Malware and tooling in Progress DataDirect GenAI Command Injection via

Malware and tooling: GitHub Copilot CLI, VS Code Copilot Chat

How Progress DataDirect GenAI Command Injection via works

CVE-2026-91140 is a critical (CVSS 9.6) OS command injection in the Progress DataDirect Autonomous REST Connector GenAI agent definitions (ARCGenAI-Generator.agent.md v2.0, ARCGenAI-Generator.prompt.md v1.0, ARCGenAI-EntityGen.agent.md v1.0). A filename derived from a crafted OpenAPI/Swagger document reaches a shell operation without validation or quoting, so shell metacharacters execute arbitrary commands. Version 2.1 of each definition fixes it. No in-the-wild exploitation or public PoC has been reported.

Progress publishes AI agent and prompt definition files in the progress/datadirect-arc-ai-model-gen GitHub repository. They drive an AI-assisted workflow, run through VS Code Copilot Chat and GitHub Copilot CLI, that converts OpenAPI/Swagger specifications into DataDirect Autonomous REST Connector (.rest) configuration files. The affected definitions are ARCGenAI-Generator.agent.md v2.0, ARCGenAI-Generator.prompt.md v1.0 and ARCGenAI-EntityGen.agent.md v1.0.

Root cause (CWE-78): a filename value derived from an OpenAPI/Swagger document was used in a shell operation without sufficient validation and quoting. Per the NVD-derived description the vulnerable logic sits in the shell-based temporary-file cleanup instructions. An attacker who can get a crafted Swagger/OpenAPI document processed can embed shell metacharacters in the filename-derived value. The shell then interprets those characters as commands when a user invokes the generator, which gives arbitrary OS command execution in the context of the user running the agent.

Impact is scoped to developer workspaces and CI environments that process untrusted API specifications with the vulnerable definitions. These hosts typically hold source code and credentials. The published CVSS 3.1 vector (AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H, score 9.6) reflects user-triggered invocation of the generator. One secondary report states no user interaction is required, and the sources disagree on this point. The NVD/OpenCVE record lists UI:R.

Remediation requires no installer or patch. Defenders pull the updated v2.1 definitions from the vendor GitHub repository; the fix (commit 7ede6d96eb033d647ffdcabf8d8069c098293575) adds filename quoting and validation safeguards. Environments that previously processed untrusted specs with vulnerable versions should be inspected for evidence of command execution. As of 2026-10-10 the CVE is not in the CISA KEV catalog, no public PoC has been identified, no exploitation has been reported, and the reported EPSS 30-day probability is 1.9%. No threat actor attribution exists and no network IOCs have been published, so no BeaconBeagle correlation was applicable.

MITRE ATT&CK techniques used in TL-2026-3226

Collection

T1005 Data from Local System

Execution

T1059.004 Command and Scripting Interpreter: Unix Shell; T1203 Exploitation for Client Execution; T1204.002 User Execution: Malicious File

Initial Access

T1195 Supply Chain Compromise

Credential Access

T1552.001 Unsecured Credentials: Credentials In Files

Affected products and versions in Progress DataDirect GenAI Command Injection via

  • Progress Software — DataDirect Autonomous REST Connector GenAI Agents (ARCGenAI-Generator.agent.md)
    Vulnerable versions: 2.0
    Fixed in: 2.1
  • Progress Software — DataDirect Autonomous REST Connector GenAI Agents (ARCGenAI-Generator.prompt.md)
    Vulnerable versions: 1.0
    Fixed in: 2.1
  • Progress Software — DataDirect Autonomous REST Connector GenAI Agents (ARCGenAI-EntityGen.agent.md)
    Vulnerable versions: 1.0
    Fixed in: 2.1

Remediation for Progress DataDirect GenAI Command Injection via

Patches

  • Progress DataDirect Autonomous REST Connector GenAI agent definitions v2.1 (fix commit 7ede6d96eb033d647ffdcabf8d8069c098293575)

Immediate actions

  • Update ARCGenAI-Generator.agent.md, ARCGenAI-Generator.prompt.md and ARCGenAI-EntityGen.agent.md to v2.1 from the progress/datadirect-arc-ai-model-gen GitHub repository
  • Do not process untrusted Swagger/OpenAPI documents with versions prior to 2.1
  • Review developer workspaces and CI environments that processed untrusted specs with vulnerable definitions for evidence of command execution

Workarounds

  • Avoid running the generator on untrusted OpenAPI/Swagger documents until upgraded

Longer-term hardening

  • Treat third-party OpenAPI/Swagger specifications as untrusted input in AI-assisted developer and CI workflows
  • Run AI agent tooling in isolated environments with least-privilege credentials
  • Monitor shell child processes spawned by Copilot CLI and VS Code agent sessions

CVEs associated with Progress DataDirect GenAI Command Injection via

CVE-2026-91140

Weaknesses (CWE) in Progress DataDirect GenAI Command Injection via

CWE-78

Timeline of Progress DataDirect GenAI Command Injection via

  • Fix commit 7ede6d96eb033d647ffdcabf8d8069c098293575 in progress/datadirect-arc-ai-model-gen adds filename quoting and validation safeguards (commit referenced by the CVE record on 2026-10-06; exact commit time not stated in sources)
  • CVE-2026-91140 published with CVSS 3.1 score 9.6 (CRITICAL) and CWE-78
  • Progress publishes its DataDirect critical security alert bulletin for CVE-2026-91140 and releases v2.1 of the affected agent definitions
  • GBHackers, SecurityOnline and other outlets report the flaw; sources note no confirmed in-the-wild exploitation, no public PoC and an EPSS 30-day score of 1.9%
  • CVE record last updated; not listed in the CISA KEV catalog
  • Threadlinqs research review: still no reported exploitation, public PoC, attribution or network IOCs in available sources

Sources cited for Progress DataDirect GenAI Command Injection via

Detection coverage for TL-2026-3226

As of 2026-10-10, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-3226 across Splunk SPL, Microsoft KQL and Sigma, covering 12 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.

9 detection rules (Splunk SPL, Microsoft KQL, Sigma) · Blue and above. Compare plans
12 indicators of compromise · Red and above. Compare plans

Threadlinqs Intelligence — Real-Time Threat Detection Platform

[ 0 threats ] [ 0 det ] [ CRIT: 0 ] [ HIGH: 0 ]
// threat_feed
$ sort --newest
Showing all threats

Live intelligence console

Threat level
Fig. 01 · Threat weatherIndexing the archive…
1 square = 1 threat · click to open

Latest Threats