What happened
An OS command injection in the shell-based temporary-file cleanup instructions of the Progress ARC GenAI generator (CVE-2026-91140, CVSS 9.6) lets an attacker who supplies a crafted Swagger/OpenAPI document execute arbitrary commands on a developer's machine when the generator is invoked to build an AI agent from that API spec. Fixed in version 2.1.
Why it matters
Developers feed untrusted API specs (from public registries, vendor exports, pull requests) into AI-agent generators; a malicious OpenAPI document escalates from 'agent config' to arbitrary code execution on the developer machine that runs the generator — including access to dev credentials and the generated agent's secrets. Classic agent-supply-chain code execution.
Attack vector
Craft a Swagger/OpenAPI document whose embedded cleanup instructions carry OS commands; execute the generator on it to run commands on the developer's machine.
Affected systems
Progress DataDirect Autonomous REST Connector GenAI Agents (ARCGenAI-Generator) 2.0, fixed in 2.1
Mitigation
Update ARCGenAI-Generator to 2.1 (see Progress DataDirect bulletin); treat untrusted OpenAPI documents as malicious input.