TGViewer
SITREP - Independent OSINT Channel SITREP - Independent OSINT Channel @sitreports · 23K subscribers
Post #39532 242
🤖 Progress DataDirect agent flaw enables OS command execution

Progress disclosed CVE-2026-91140, a critical command injection issue in early-access DataDirect Autonomous REST Connector AI Model Generator agents. A crafted OpenAPI/Swagger file can pass shell metacharacters through a filename field and trigger arbitrary OS commands when the DataDirect ARC AI Model Generator processes it. Fixed agent definitions are available in version 2.1.

The exposure sits in developer workspaces and CI runners, where successful execution can reach source code, tokens, and cloud credentials. Detection is limited because Progress notes no specific product error message; review environments that handled untrusted API specs and replace affected agent files.

🛰️ Open sources - closed narratives
@sitreports
More from @sitreports
  1. Oct 8, 2026🔍 SonicWall patches CVSS 10 pre-auth flaw in SMA1000 SonicWall has issued hotfixes for fo…
  2. Oct 8, 2026🤖 Pentagon starts AI pilot for classification control The Pentagon will begin a small-sca…
  3. Oct 8, 2026🤖 GitHub Copilot CLI prompt chain can exfiltrate local secrets Adversa AI disclosed a Cry…
  4. Oct 8, 2026🔍 Eight npm packages used to push Overlord RAT and stealer Eight malicious npm packages w…
  5. Oct 8, 2026📝You reap what you sow📝 Ukrainians lose South Korean ambassador The Kryvyi Rih school of…
  6. Oct 8, 2026🤖 PoeLLM Malware Expands Cryptojacking Footprint PoeLLM has reportedly infected more than…
Threads Profile ViewerView any public Threads profile without an account.Open ThreadLook →Writing with AI? Make it sound human.Metric37 rewrites AI drafts so they read naturally. Free AI detector, 1,500 words free.Try Metric37 →