← back
CVE-2026-42078mediumCWE-22

PPTAgent: Arbitrary File Write + Directory Creation via markdown_table_to_image

13Vexday Risk Score

No sign of exploitation. No public exploitation artifact known so far.

ssvc Trackcvss 4.6epss 0.2%
exploitation probability
0.2%top 90% of all CVEs
observed exploitation
nono source reports it
PPTAgent is an agentic framework for reflective PowerPoint generation. Prior to commit 418491a, PPTAgent is vulnerable to arbitrary file write and directory creation via markdown_table_to_image. This issue has been patched via commit 418491a.
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:L/A:L
Affected products
icip-cas · PPTAgent