Sceawere

Vulnerability Detail

CVE-2026-91140UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

OS Command Injection in ARCGenAI-Generator

Vulnerability Metadata

Severity
Critical
Score / CVSS
9.6
Creation Date
11h ago
Vendor
Progress Software
Product
Autonomous REST Connector GenAI Agents
Attack Type
CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
Vector String
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H
Attack Complexity
LOW

Narrative and Response

Description

An OS command injection vulnerability in the shell-based temporary-file cleanup instructions in Progress Software Autonomous REST Connector GenAI Agents ARCGenAI-Generator version 2.0 allows an attacker who supplies a crafted Swagger/OpenAPI document to execute arbitrary commands on a developer's machine when a user invokes the generator.

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "9.6",
  "pubDate": "2026-10-06T14:17:48.407Z",
  "pubdate": "2026-10-06T14:17:48.407Z",
  "executiveSummary": "Progress Software Autonomous REST Connector GenAI Agents ARCGenAI-Generator version 2.0 contains an OS command injection vulnerability within its temporary-file cleanup routine. The flaw resides in the handling of user-supplied Swagger/OpenAPI documentation files during the code generation process.\nBy crafting a malicious OpenAPI document, an attacker can trigger the execution of arbitrary operating system commands with the privileges of the developer running the generator. This vulnerability poses a significant risk to the software development lifecycle, as it effectively allows for remote code execution on the local workstation of the developer invoking the generator. Exploitation requires the developer to process an untrusted or maliciously modified document. No authentication or elevated privileges are required within the generator itself to trigger the flaw, as the malicious payload is embedded within the input data processed by the application.\nThe successful exploitation of this vulnerability could lead to a complete compromise of the developer's local environment, facilitating data exfiltration, lateral movement within the development network, or the injection of malicious code into the generated project artifacts.",
  "technicalDetails": "The vulnerability is an OS command injection flaw located in the temporary-file cleanup instructions of the Progress Software Autonomous REST Connector GenAI Agents (ARCGenAI-Generator) version 2.0. The root cause is improper sanitization of inputs derived from Swagger/OpenAPI files that are passed to system-level shell commands during the cleanup phase of the generator's execution cycle.\nWhen a user provides a Swagger or OpenAPI document, the generator parses the file to derive service metadata. During this process, or subsequent cleanup routines, the application constructs shell commands to manage temporary file operations. The application fails to adequately escape or validate characters within specific fields of the OpenAPI document that are incorporated into these shell commands. Consequently, an attacker can inject shell metacharacters (such as backticks, semicolons, or pipe symbols) into these fields to terminate the intended command and execute arbitrary malicious instructions.\nThe attack flow follows these steps: 1. The attacker creates a malicious OpenAPI document containing an embedded OS command within a field (e.g., in a metadata, server URL, or description field) that the generator process inadvertently includes in its cleanup logic. 2. The attacker delivers the document to a developer, who then uses the ARCGenAI-Generator to process the file. 3. As the generator performs its cleanup operations, it invokes a system shell (e.g., /bin/sh or cmd.exe) to delete or move temporary files. 4. The shell interprets the injected metacharacters, executing the attacker-supplied payload with the context of the user running the generator. 5. The malicious code executes on the host system, bypassing the generator’s intended scope.\nBecause the generator executes these commands locally, the impact is confined to the developer's machine but potentially severe. The attacker gains the ability to execute any command permitted by the developer's account privileges. Post-exploitation impact includes unauthorized file system access, modification of project source code, potential credential theft from configuration files or local environment variables, and the ability to establish persistent access on the development workstation. This vulnerability highlights the danger of passing untrusted input directly to shell execution functions without rigorous validation or the use of safe API alternatives that avoid shell interpretation."
}
CVE-2026-91140: OS Command Injection in ARCGenAI-Generator (CRITICAL Severity, CVSS: 9.6) | Sceawere