PT-2026-36857 · Pptagent · Pptagent

·

CVE-2026-42079

·

Published

2026-05-04

·

Updated

2026-07-13

CVSS v3.1

8.6

High

VectorAV:L/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions PPTAgent versions prior to commit 418491a
Description An agentic framework for reflective PowerPoint generation allows arbitrary code execution. This occurs because the software uses the Python eval() function to process code generated by a Large Language Model (LLM) while builtins are in scope.
Recommendations Update to the version containing commit 418491a.

Exploit

Fix

Eval Injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-42079
GHSA-89G2-XW5C-V95P
PYSEC-2026-2892

Affected Products

Pptagent