Repository navigation
Security Fix: CVE-2026-91140
This release remediates CVE-2026-91140, a command-injection/unsafe-file-path issue where Swagger-derived {fileName} and {entity-name} values could be used unsafely in generated shell cleanup and file-write instructions.
Fixes:
- Enforced a strict allowlist (
^[A-Za-z0-9._-]+$) for{fileName}/{entity-name}, rejecting anything ambiguous instead of trying to sanitize it. - Quoted all
{fileName}expansions in shell cleanup/verification commands and preferred native file deletion over shell commands. - Closed a Windows-specific bypass allowing trailing-dot names (e.g.
foo.) and reserved device names (e.g.CON,NUL,COM1) that the allowlist alone didn't catch.
More information: https://community.progress.com/s/article/Progress-DataDirect-Critical-Security-Alert-Bulletin-September-2026-CVE-2026-91140
Also included: removed internal agent/document version markers in favor of tracking releases via GitHub Releases.
Full Changelog: v2.0...v2.1