CVE-2026-91140
CRITICAL
NVD
CVSS Score
9.6
Severity
CRITICAL
Published
Oct 06, 2026
Vendor
unknown
Description
An OS command injection vulnerability in the shell-based temporary-file cleanup instructions in Progress Software Autonomous REST Connector GenAI Agents ARCGenAI-Generator version 2.0 allows an attacker who supplies a crafted Swagger/OpenAPI document to execute arbitrary commands on a developer's machine when a user invokes the generator.