Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
Github GHSA |
GHSA-89g2-xw5c-v95p | PPTAgent: Arbitrary Code Execution via Python eval() of LLM-Generated Code with Builtins in Scope |
Mon, 04 May 2026 20:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Mon, 04 May 2026 20:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Icip-cas
Icip-cas pptagent |
|
| Vendors & Products |
Icip-cas
Icip-cas pptagent |
Mon, 04 May 2026 17:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | PPTAgent is an agentic framework for reflective PowerPoint generation. Prior to commit 418491a, PPTAgent is vulnerable to arbitrary code execution via Python eval() of LLM-generated code with builtins in scope. This issue has been patched via commit 418491a. | |
| Title | PPTAgent: Arbitrary Code Execution via Python eval() of LLM-Generated Code with Builtins in Scope | |
| Weaknesses | CWE-95 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2026-05-04T19:42:53.677Z
Reserved: 2026-04-23T19:17:30.565Z
Link: CVE-2026-42079
Updated: 2026-05-04T19:41:47.219Z
Status : Deferred
Published: 2026-05-04T17:16:24.887
Modified: 2026-05-05T20:19:04.323
Link: CVE-2026-42079
No data.
OpenCVE Enrichment
Updated: 2026-05-04T19:43:57Z
Github GHSA