πŸ” CVE Alert

CVE-2026-101947

UNKNOWN 0.0

ExifTool for photo and video 5.0.1 - Local OS command injection through filenames during CSV export

CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th

ExifTool for photo and video 5.0.1-gms by CellHubs constructs shell command strings from file paths and invokes /system/bin/sh -c. In the CSV-export path, the selected media path is merely surrounded with single quotes; embedded single quotes are not escaped.

CWE CWE-78
Vendor cellhubs
Product exiftool for photo and video
Published Oct 10, 2026
Stay Ahead of the Next One

Get instant alerts for cellhubs exiftool for photo and video

Be the first to know when new unknown vulnerabilities affecting cellhubs exiftool for photo and video are published β€” delivered to Slack, Telegram or Discord.

Get Free Alerts β†’ Free Β· No credit card Β· 60 sec setup

Affected Versions

CellHubs / ExifTool for photo and video
5.0.1-gms

References

NVD β†— CVE.org β†— EPSS Data β†—
fluidattacks.com: https://fluidattacks.com/advisories/saturn play.google.com: https://play.google.com/store/apps/details?id=com.exiftool.free

Credits

AndrΓ©s Ramos