Progress disclosed a critical command injection flaw that lets malicious OpenAPI or Swagger documents execute OS commands.