๐Ÿ” CVE Alert

CVE-2026-42079

HIGH 8.6

PPTAgent: Arbitrary Code Execution via Python eval() of LLM-Generated Code with Builtins in Scope

CVSS Score
8.6
EPSS Score
0.0%
EPSS Percentile
0th

PPTAgent is an agentic framework for reflective PowerPoint generation. Prior to commit 418491a, PPTAgent is vulnerable to arbitrary code execution via Python eval() of LLM-generated code with builtins in scope. This issue has been patched via commit 418491a.

CWE CWE-95
Vendor icip-cas
Product pptagent
Published May 4, 2026
Stay Ahead of the Next One

Get instant alerts for icip-cas pptagent

Be the first to know when new high vulnerabilities affecting icip-cas pptagent are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

CVSS v3 Breakdown

CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H
Attack Vector
Local
Attack Complexity
Low
Privileges Required
None
User Interaction
Required
Scope
Changed
Confidentiality
High
Integrity
High
Availability
High

Affected Versions

icip-cas / PPTAgent
< 418491a9a1c02d9d93194b5973bb58df35cf9d00

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
github.com: https://github.com/icip-cas/PPTAgent/security/advisories/GHSA-89g2-xw5c-v95p github.com: https://github.com/icip-cas/PPTAgent/commit/418491a9a1c02d9d93194b5973bb58df35cf9d00