Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
Github GHSA |
GHSA-hrcw-xc63-g29m | PPTAgent: Arbitrary File Write + Directory Creation via markdown_table_to_image |
Mon, 04 May 2026 20:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Icip-cas
Icip-cas pptagent |
|
| Vendors & Products |
Icip-cas
Icip-cas pptagent |
Mon, 04 May 2026 19:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Mon, 04 May 2026 17:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | PPTAgent is an agentic framework for reflective PowerPoint generation. Prior to commit 418491a, PPTAgent is vulnerable to arbitrary file write and directory creation via markdown_table_to_image. This issue has been patched via commit 418491a. | |
| Title | PPTAgent: Arbitrary File Write + Directory Creation via markdown_table_to_image | |
| Weaknesses | CWE-22 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2026-05-04T18:38:50.608Z
Reserved: 2026-04-23T19:17:30.565Z
Link: CVE-2026-42078
Updated: 2026-05-04T18:38:42.517Z
Status : Deferred
Published: 2026-05-04T17:16:24.740
Modified: 2026-05-05T20:19:04.323
Link: CVE-2026-42078
No data.
OpenCVE Enrichment
Updated: 2026-05-04T20:00:07Z
Github GHSA