Arbitrary File Write Vulnerability in PPTAgent Framework
CVE-2026-42080

4.6MEDIUM

Key Information:

Vendor

Icip-cas

Status
Vendor
CVE Published:
4 May 2026

What is CVE-2026-42080?

The PPTAgent framework, designed for generating reflective PowerPoint presentations, contains an arbitrary file write vulnerability that allows an attacker to exploit the save_generated_slides function. This flaw, identified prior to commit 418491a, could potentially lead to unauthorized access to sensitive files or malicious content creation. Fortunately, the issue has been resolved in commit 418491a, and users are urged to update their installations to protect against potential threats.

Affected Version(s)

PPTAgent < 418491a9a1c02d9d93194b5973bb58df35cf9d00

References

CVSS V3.1

Score:
4.6
Severity:
MEDIUM
Confidentiality:
None
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.