PPTAgent: code execution and arbitrary file write flaws patched (CVE-2026-42078/79/80)
Three vulnerabilities were disclosed in PPTAgent, an agentic framework for reflective PowerPoint generation: arbitrary code execution via Python eval() of LLM-generated code with builtins in scope, and arbitrary file write/directory creation via markdown_table_to_image and save_generated_slides. All were patched in commit 418491a.
Disclosed 4 May 2026 · Record updated 13 September 2026
Impact
Attackers could achieve arbitrary code execution and write files or create directories on systems running unpatched PPTAgent versions.
Our coverage
No articles linked to this incident yet.
Sources
- nvd.nist.govhttps://nvd.nist.gov/vuln/detail/CVE-2026-42078
- nvd.nist.govhttps://nvd.nist.gov/vuln/detail/CVE-2026-42079
- nvd.nist.govhttps://nvd.nist.gov/vuln/detail/CVE-2026-42080
