CVE-2026-42079
Last modified
CVE-2026-42079 is a high-severity vulnerability rated 8.6/10 on the CVSS scale. PPTAgent is an agentic framework for reflective PowerPoint generation. Prior to commit 418491a, PPTAgent is vulnerable to arbitrary code execution via Python eval() of LLM-generated code with builtins in scope. EPSS estimates a 0.14% chance of exploitation in the next 30 days.
Description
PPTAgent is an agentic framework for reflective PowerPoint generation. Prior to commit 418491a, PPTAgent is vulnerable to arbitrary code execution via Python eval() of LLM-generated code with builtins in scope. This issue has been patched via commit 418491a.
Metrics
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H
Weakness Enumeration
References
Timeline
- Published
- Last Modified
- Status
- Deferred
Frequently Asked Questions
What is CVE-2026-42079?
How severe is CVE-2026-42079?
How do I fix CVE-2026-42079?
Are you affected by CVE-2026-42079?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
