Skip to content

v2.1

Latest

Choose a tag to compare

@cassie-manning cassie-manning released this 18 Sep 17:41
1067a25

Security Fix: CVE-2026-91140

This release remediates CVE-2026-91140, a command-injection/unsafe-file-path issue where Swagger-derived {fileName} and {entity-name} values could be used unsafely in generated shell cleanup and file-write instructions.

Fixes:

  • Enforced a strict allowlist (^[A-Za-z0-9._-]+$) for {fileName}/{entity-name}, rejecting anything ambiguous instead of trying to sanitize it.
  • Quoted all {fileName} expansions in shell cleanup/verification commands and preferred native file deletion over shell commands.
  • Closed a Windows-specific bypass allowing trailing-dot names (e.g. foo.) and reserved device names (e.g. CON, NUL, COM1) that the allowlist alone didn't catch.

More information: https://community.progress.com/s/article/Progress-DataDirect-Critical-Security-Alert-Bulletin-September-2026-CVE-2026-91140

Also included: removed internal agent/document version markers in favor of tracking releases via GitHub Releases.

Full Changelog: v2.0...v2.1