CVE-2026-42079
HIGHPPTAgent: Arbitrary Code Execution via Python eval() of LLM-Generated Code with Builtins in Scope
Title source: cnaDescription
PPTAgent is an agentic framework for reflective PowerPoint generation. Prior to commit 418491a, PPTAgent is vulnerable to arbitrary code execution via Python eval() of LLM-generated code with builtins in scope. This issue has been patched via commit 418491a.
References (2)
Core 2
Core References
X_Refsource_Confirm x_refsource_confirm
https://github.com/icip-cas/PPTAgent/security/advisories/GHSA-89g2-xw5c-v95p
X_Refsource_Misc x_refsource_misc
https://github.com/icip-cas/PPTAgent/commit/418491a9a1c02d9d93194b5973bb58df35cf9d00
Scores
CVSS v3
8.6
EPSS
0.0002
EPSS Percentile
6.5%
Attack Vector
LOCAL
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H
CISA SSVC
Vulnrichment
Exploitation
poc
Automatable
no
Technical Impact
total
Details
CWE
CWE-95
Status
published
Products (2)
icip-cas/PPTAgent
< 418491a9a1c02d9d93194b5973bb58df35cf9d00
pypi/pptagent
0 - 1.1.36PyPI
Published
May 04, 2026
Tracked Since
May 04, 2026