<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-06T09:16:05.206203+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/cve-2026-42079</id>
    <title>CVE-2026-42079 — PPTAgent: Arbitrary Code Execution via Python eval() of LLM-Generated Code with Builtins in Scope</title>
    <updated>2026-10-06T09:16:05.207979+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> icip-cas PPTAgent</p>
<p>PPTAgent is an agentic framework for reflective PowerPoint generation. Prior to commit 418491a, PPTAgent is vulnerable to arbitrary code execution via Python eval() of LLM-generated code with builtins in scope. This issue has been patched via commit 418491a.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/cve-2026-42079"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-89g2-xw5c-v95p</id>
    <title>GHSA-89g2-xw5c-v95p — PPTAgent: Arbitrary Code Execution via Python eval() of LLM-Generated Code with Builtins in Scope</title>
    <updated>2026-10-06T09:16:05.208032+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> PyPI: pptagent</p>
<p>## Summary</p>
<p>&gt; This vulnerability has been fixed in https://github.com/icip-cas/PPTAgent/commit/418491a9a1c02d9d93194b5973bb58df35cf9d00.</p>
<p>`CodeExecutor.execute_actions` (pptagent/apis.py:126-205) processes LLM-generated slide editing actions using Python's `eval()`:</p>
<p>```python
# pptagent/apis.py:184-186
partial_func = partial(self.registered_functions[func], edit_slide)
if func == "replace_image":
    partial_func = partial(partial_func, doc)
eval(line, {}, {func: partial_func})              # ← builtins accessible
```</p>
<p>The call `eval(line, {}, {func: partial_func})` passes an empty dict as globals. Per Python's language reference: "If the globals dictionary is present and does not contain a value for the key `__builtins__`, a reference to the dictionary of the built-in module builtins is inserted under that key before the expression is parsed." **This means `__import__`, open, exec, compile, and all other built-in functions are available inside the evaluated expression**.</p>
<p>The validation before eval only checks 1) The function name matches ^[a-z]+_[a-z_]+ (snake_case pattern) and 2) The function name is in self.registered_functions.</p>
<p>The arguments to the function are not validated. If an attacker can influence the LLM's generated edit actions (via prompt injection through slide content, document content, or the command_list context), the following payload would execute arbitrary code:</p>
<p>```python
# Attacker-controlled slide content feeds into the command_list context
# The…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-89g2-xw5c-v95p"/>
  </entry>
</feed>
