Progress DataDirect ARCGenAI Proxy Exposes to Serious Command Injection Vulnerability
2026-10-07 09:43:54
According to CoinMeta, Progress Software disclosed this week that its DataDirect autonomous REST connector ARCGenAI proxy has a severe command injection vulnerability, identified as CVE-2026-91140, with a severity score of 9.6. Attackers can execute arbitrary operating system commands on the developer's machine. The trigger condition is the embedding of a shell meta-character in the file name within a OpenAPI or Swagger document. When developers call the ARCGenAI generator, this tool runs a cleanup routine based on shell on temporary files, and this routine directly uses the file name without sufficient validation or reference. This issue was fixed in version 2.1 of the proxy definition, and so far, no actual cases of exploiting this vulnerability have been confirmed.
Source:Forkast
This content is for market information only and does not constitute investment advice.
Follow HKWDB official accounts to stay updated

Hot Articles
Refresh

Bitcoin October 2026 Outlook: Can the 19% Historical Gain Hold?
09-30 12:57

Dogecoin Price: Whales Buy $112M, Can DOGE Break $0.10?
09-29 12:48

What is Solidigm? Is Its $150B IPO Valuation a Bubble?
09-28 13:00

Is PAXG Stable? Is Gold-Backed Better Than Stablecoins?
09-24 18:04

ETH Rebounds to $2,800: Can It Hold $3,200 by Month-End?
09-23 11:07



