<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Tue, 06 Oct 2026 09:16:04 +0000</lastBuildDate>
    <item>
      <title>CVE-2026-42079 — PPTAgent: Arbitrary Code Execution via Python eval() of LLM-Generated Code with Builtins in Scope</title>
      <link>https://cve.radiocsirt.org/vuln/cve-2026-42079</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; icip-cas PPTAgent&lt;/p&gt;
&lt;p&gt;PPTAgent is an agentic framework for reflective PowerPoint generation. Prior to commit 418491a, PPTAgent is vulnerable to arbitrary code execution via Python eval() of LLM-generated code with builtins in scope. This issue has been patched via commit 418491a.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; icip-cas PPTAgent&lt;/p&gt;
&lt;p&gt;PPTAgent is an agentic framework for reflective PowerPoint generation. Prior to commit 418491a, PPTAgent is vulnerable to arbitrary code execution via Python eval() of LLM-generated code with builtins in scope. This issue has been patched via commit 418491a.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/cve-2026-42079</guid>
    </item>
    <item>
      <title>GHSA-89g2-xw5c-v95p — PPTAgent: Arbitrary Code Execution via Python eval() of LLM-Generated Code with Builtins in Scope</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-89g2-xw5c-v95p</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; PyPI: pptagent&lt;/p&gt;
&lt;p&gt;## Summary&lt;/p&gt;
&lt;p&gt;&amp;gt; This vulnerability has been fixed in https://github.com/icip-cas/PPTAgent/commit/418491a9a1c02d9d93194b5973bb58df35cf9d00.&lt;/p&gt;
&lt;p&gt;`CodeExecutor.execute_actions` (pptagent/apis.py:126-205) processes LLM-generated slide editing actions using Python&amp;#39;s `eval()`:&lt;/p&gt;
&lt;p&gt;```python
# pptagent/apis.py:184-186
partial_func = partial(self.registered_functions[func], edit_slide)
if func == &amp;#34;replace_image&amp;#34;:
    partial_func = partial(partial_func, doc)
eval(line, {}, {func: partial_func})              # ← builtins accessible
```&lt;/p&gt;
&lt;p&gt;The call `eval(line, {}, {func: partial_func})` passes an empty dict as globals. Per Python&amp;#39;s language reference: &amp;#34;If the globals dictionary is present and does not contain a value for the key `__builtins__`, a reference to the dictionary of the built-in module builtins is inserted under that key before the expression is parsed.&amp;#34; **This means `__import__`, open, exec, compile, and all other built-in functions are available inside the evaluated expression**.&lt;/p&gt;
&lt;p&gt;The validation before eval only checks 1) The function name matches ^[a-z]+_[a-z_]+ (snake_case pattern) and 2) The function name is in self.registered_functions.&lt;/p&gt;
&lt;p&gt;The arguments to the function are not validated. If an attacker can influence the LLM&amp;#39;s generated edit actions (via prompt injection through slide content, document content, or the command_list context), the following payload would execute arbitrary code:&lt;/p&gt;
&lt;p&gt;```python
# Attacker-controlled slide content feeds into the command_list context
# The…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; PyPI: pptagent&lt;/p&gt;
&lt;p&gt;## Summary&lt;/p&gt;
&lt;p&gt;&amp;gt; This vulnerability has been fixed in https://github.com/icip-cas/PPTAgent/commit/418491a9a1c02d9d93194b5973bb58df35cf9d00.&lt;/p&gt;
&lt;p&gt;`CodeExecutor.execute_actions` (pptagent/apis.py:126-205) processes LLM-generated slide editing actions using Python&amp;#39;s `eval()`:&lt;/p&gt;
&lt;p&gt;```python
# pptagent/apis.py:184-186
partial_func = partial(self.registered_functions[func], edit_slide)
if func == &amp;#34;replace_image&amp;#34;:
    partial_func = partial(partial_func, doc)
eval(line, {}, {func: partial_func})              # ← builtins accessible
```&lt;/p&gt;
&lt;p&gt;The call `eval(line, {}, {func: partial_func})` passes an empty dict as globals. Per Python&amp;#39;s language reference: &amp;#34;If the globals dictionary is present and does not contain a value for the key `__builtins__`, a reference to the dictionary of the built-in module builtins is inserted under that key before the expression is parsed.&amp;#34; **This means `__import__`, open, exec, compile, and all other built-in functions are available inside the evaluated expression**.&lt;/p&gt;
&lt;p&gt;The validation before eval only checks 1) The function name matches ^[a-z]+_[a-z_]+ (snake_case pattern) and 2) The function name is in self.registered_functions.&lt;/p&gt;
&lt;p&gt;The arguments to the function are not validated. If an attacker can influence the LLM&amp;#39;s generated edit actions (via prompt injection through slide content, document content, or the command_list context), the following payload would execute arbitrary code:&lt;/p&gt;
&lt;p&gt;```python
# Attacker-controlled slide content feeds into the command_list context
# The…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-89g2-xw5c-v95p</guid>
    </item>
  </channel>
</rss>
