๐Ÿ” CVE Alert

CVE-2026-7580

MEDIUM 5.3

Exiftool JPEG/QuickTime/MOV/MP4 GM.pm Process_mrld code injection

CVSS Score
5.3
EPSS Score
0.0%
EPSS Percentile
0th

A vulnerability was detected in Exiftool up to 13.53. Impacted is the function Process_mrld of the file lib/Image/ExifTool/GM.pm of the component JPEG/QuickTime/MOV/MP4. The manipulation of the argument -ee results in code injection. Attacking locally is a requirement. Upgrading to version 13.54 is recommended to address this issue. The patch is identified as 5a8b6b6ead12b39e3f32f978a4efd0233facbb01. It is suggested to upgrade the affected component. The fix in the source code mentions: "[J]ust to be safe, probably never happen".

CWE CWE-94 CWE-74
Vendor n/a
Product exiftool
Published May 1, 2026
Stay Ahead of the Next One

Get instant alerts for n/a exiftool

Be the first to know when new medium vulnerabilities affecting n/a exiftool are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

CVSS v3 Breakdown

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L/E:P/RL:O/RC:C
Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality
Integrity
Availability

Affected Versions

n/a / Exiftool
13.0 13.1 13.2 13.3 13.4 13.5 13.6 13.7 13.8 13.9 13.10 13.11 13.12 13.13 13.14 13.15 13.16 13.17 13.18 13.19 13.20 13.21 13.22 13.23 13.24 13.25 13.26 13.27 13.28 13.29 13.30 13.31 13.32 13.33 13.34 13.35 13.36 13.37 13.38 13.39 13.40 13.41 13.42 13.43 13.44 13.45 13.46 13.47 13.48 13.49 13.50 13.51 13.52 13.53

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
vuldb.com: https://vuldb.com/vuln/360421 vuldb.com: https://vuldb.com/vuln/360421/cti vuldb.com: https://vuldb.com/submit/800049 youtu.be: https://youtu.be/WktMPapQxlM github.com: https://github.com/exiftool/exiftool/commit/5a8b6b6ead12b39e3f32f978a4efd0233facbb01#diff-5a95c56c6f98f0aa538233fd81bb9967154f3e9ebd4126a98dfb126c4c5629a4 github.com: https://github.com/exiftool/exiftool/commit/5a8b6b6ead12b39e3f32f978a4efd0233facbb01 github.com: https://github.com/exiftool/exiftool/releases/tag/13.54 github.com: https://github.com/exiftool/exiftool/

Credits

๐Ÿ” ilyass-armadin (VulDB User) VulDB CNA Team