External risk intelligence

Progress ARCGenAI-Generator OS Command Injection Vulnerability

CVE advisorySeverity: CRITICAL (CVSS 9.6)

CVE-2026-91140

This vulnerability affects a development tool used for generating code from Swagger/OpenAPI documents. It executes on the developer's local machine during the development process and is not a network-facing service, edge gateway, or public-facing endpoint in standard deployments.

OS Command Injection

Halo Surface Signal: 1 out of 5 — much less likely to be public-facing.

External exposure likelihood

Horizon Alert

Summary of the vulnerability and why it matters

An OS command injection vulnerability has been identified in a Progress Software tool used for generating code from API specifications. If a user processes a specially crafted API document, an attacker could execute commands on a developer's machine. The main concern is confirming relevance and exposure.

  • Unsafe code generation can run unauthorized commands.
  • Affects developer tools, not typically live systems.
  • Verify if this development tool is in use.

Attack Path

How an attacker could exploit the issue

An attacker could trick a developer into processing a malicious Swagger document, leading to the execution of arbitrary commands on their machine. This occurs because the tool's temporary file cleanup process is vulnerable to command injection when parsing a crafted input. If a user invokes this generator with a specially designed document, an attacker can leverage this flaw.

  • Attacker must trick user into processing crafted document.
  • Vulnerability triggered when generating code from input.
  • Risk of arbitrary command execution on developer machine.

Live Threat

Current exploitation, exposure, and threat context

A developer's machine could be at risk when processing a crafted Swagger/OpenAPI document with the generator. This could lead to arbitrary command execution on the developer's local system.

  • Developer machine commands could be executed.
  • Malicious commands may run via crafted documents.
  • Arbitrary code execution on local systems.

Operational Fix

Recommended remediation, mitigation, and detection steps

This OS command injection vulnerability affects the REST Connector GenAI Agents, specifically impacting developers when they use the generator with a crafted Swagger/OpenAPI document. The first practical move is for development teams to identify instances of the generator, confirm its reachability and criticality in their workflows, and then coordinate with vendor management for a timely resolution to mitigate the risk of arbitrary command execution on developer machines.

  • Development teams should own remediation.
  • Verify generator use and exposure.
  • Coordinate vendor fix implementation.

Supplementary metadata

Validate whether this threat affects your internet-facing exposure.

Halo Threat Intelligence helps prioritize remediation with Halo Surface Signal and H/A/L/O context. Start exposure validation with a free external attack surface trial.

Frequently asked questions

What is Progress Autonomous REST Connector GenAI Agents?

This software is a development tool used to automate the creation of code based on Swagger or OpenAPI specifications. Developers use it to accelerate API integration tasks by generating the necessary connector logic from existing API documentation.

What does CWE-78 mean for CVE-2026-91140?

CWE-78 refers to OS Command Injection. In this CVE, it means the software fails to properly sanitize inputs before passing them to the underlying system shell. Because of this, a specially crafted API document can trick the tool into running unauthorized commands on the developer's computer.

How is this command injection triggered?

The vulnerability is triggered only when a developer actively uses the generator to process a malicious Swagger or OpenAPI file. Simply having the tool installed on a system does not trigger the flaw; it requires a user to invoke the generator with the crafted document.

Is my network at risk from this vulnerability?

Halo Surface Signal indicates this is very unlikely because the tool is a local development utility, not a network-facing service or public endpoint. The risk is localized to the developer's workstation rather than the broader network infrastructure.

Do I need to patch the ARCGenAI-Generator?

Yes, if your team uses this tool. Your first step is to identify all developer machines running this version. Coordinate with your vendor management team to track and implement the official fix, ensuring that your local development environments remain secure.

References