Back Tech.Yahoo A Filename Becomes a Weapon: Progress DataDirect's ARCGenAI Agents Hit by Critical ...
Progress Software disclosed a critical vulnerability this week in its DataDirect Autonomous REST Connector GenAI Agents. Tracked as CVE-2026-91140 , the flaw carries a CVSS score of 9.6 and allows an attacker to execute arbitrary operating system commands on a developer's machine. The trigger is deceptively simple: a crafted OpenAPI or Swagger document with shell metacharacters embedded in a filename.
When a developer invokes the ARCGenAI generator, the tool runs a shell-based cleanup routine on temporary files. That routine takes the filename from the spec without sufficient validation or quoting. The shell interprets the metacharacters as instructions. The developer's machine runs whatever the attacker wrote.
Progress has patched the issue in version 2.1 of the agent definitions. No in-the-wild exploitation has been confirmed, and no public proof-of-concept exists at the time of disclosure. But the patch is not the interesting part.
The pattern behind the patch
This is not an isolated bug. It is the latest entry in a growing class of supply-chain vulnerabilities where AI agents treat configuration specifications as trusted input rather than untrusted data.
Earlier this year, security researchers documented CVE-2025-54135 (CurXecute) and CVE-2025-54136 (MCPoison) in the Cursor IDE, where a malicious MCP server could overwrite configuration files and execute attacker commands. CVE-2025-53773 in GitHub Copilot allowed source code and issues to flip a developer's auto-approve setting, disabling confirmation for tool calls. The mechanism differs each time, but the structural failure is the same: the agent ingests a spec, a descriptor, or a configuration file and acts on it without treating it as adversarial input.
Phoenix Security's mid-2026 data puts numbers behind the pattern. Of 59 tracked supply-chain campaigns, AI-agent tooling was confirmed as a delivery mechanism in 14. Zero CVEs were assigned during active exploitation. The gap between incident and formal vulnerability tracking is itself a risk factor.
The connection to protocol-level exposure
We have covered this structural vulnerability from multiple angles. ClawSecure's October disclosure of spec-level flaws in MCP's auto-fetch behavior showed that the protocol itself can be weaponized — when content is created in platforms like Notion or Linear, the MCP server automatically fetches attacker-controlled links with no AI interaction required. That finding targeted the MCP specification, not individual vendor implementations.
The testing infrastructure gap we identified earlier makes these findings harder to catch before they reach production. There is no official conformance test suite for MCP. No security certification standard. No automated compliance check that would flag a shell-based cleanup routine passing unvalidated filenames to a system shell.
Progress DataDirect's vulnerability is a different product, a different protocol, and a different attack surface. But it sits in the same structural category: an agent tool that processes external specifications without sufficient boundary enforcement between data ingestion and system-level execution.
What builders should take from this
The implications for infrastructure decision-makers are concrete. First, every agent tool that ingests OpenAPI, Swagger, MCP descriptors, or any external specification file should be treated as processing untrusted user input. Sanitization must happen before any interaction with the operating system, not after. Second, shell-based file operations in agent generators are an unnecessary architectural risk. Language-native APIs that avoid shell interpretation entirely eliminate this class of vulnerability at the design level. Third, the absence of standardized testing infrastructure means individual teams must build their own validation layers — a cost that scales with adoption.
The Veracode 2026 GenAI Code Security Report found a 56% security pass rate for AI-generated code, unchanged from the prior year. The rate is not improving because the underlying architecture — agents treating specs as trusted, shells as safe, configurations as benign — has not changed.
Progress patched version 2.1. The fix is necessary. But until the industry stops treating configuration files as data that happens to be safe rather than data that might be adversarial, this class of vulnerability will keep recurring across every tool that automates spec ingestion.
A note on verification
No confirmed breaches related to CVE-2026-91140 have been publicly documented. Progress reports no known in-the-wild exploitation. The broader supply-chain pattern described here is drawn from independent security research by Phoenix Security, Veracode, and prior Forkast reporting on ClawSecure's findings. Individual vendor research should be contextualized accordingly — security vendors have products to sell, and independent replication of findings varies.
The full story
This article is one source in a clustered incident — the cluster page carries the summary, timeline and every other outlet covering it.
