CVE-2026-101947
ExifTool for photo and video 5.0.1 - Local OS command injection through filenames during CSV export
CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th
ExifTool for photo and video 5.0.1-gms by CellHubs constructs shell command strings from file paths and invokes /system/bin/sh -c. In the CSV-export path, the selected media path is merely surrounded with single quotes; embedded single quotes are not escaped.
| CWE | CWE-78 |
| Vendor | cellhubs |
| Product | exiftool for photo and video |
| Published | Oct 10, 2026 |
Stay Ahead of the Next One
Get instant alerts for cellhubs exiftool for photo and video
Be the first to know when new unknown vulnerabilities affecting cellhubs exiftool for photo and video are published β delivered to Slack, Telegram or Discord.
Get Free Alerts β
Free Β· No credit card Β· 60 sec setup
Affected Versions
CellHubs / ExifTool for photo and video
5.0.1-gms
References
Credits
AndrΓ©s Ramos