CVE-2026-42078
Last modified
CVE-2026-42078 is a medium-severity vulnerability rated 4.6/10 on the CVSS scale. PPTAgent is an agentic framework for reflective PowerPoint generation. Prior to commit 418491a, PPTAgent is vulnerable to arbitrary file write and directory creation via markdown_table_to_image. EPSS estimates a 0.20% chance of exploitation in the next 30 days.
Description
PPTAgent is an agentic framework for reflective PowerPoint generation. Prior to commit 418491a, PPTAgent is vulnerable to arbitrary file write and directory creation via markdown_table_to_image. This issue has been patched via commit 418491a.
Metrics
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:L/A:L
Weakness Enumeration
References
Timeline
- Published
- Last Modified
- Status
- Deferred
Frequently Asked Questions
What is CVE-2026-42078?
How severe is CVE-2026-42078?
How do I fix CVE-2026-42078?
Are you affected by CVE-2026-42078?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
