CVE-2026-101947 PUBLISHED

ExifTool for photo and video 5.0.1 - Local OS command injection through filenames during CSV export

Assigner: Fluid Attacks
Reserved: 28.09.2026 Published: 10.10.2026 Updated: 10.10.2026

ExifTool for photo and video 5.0.1-gms by CellHubs constructs shell command strings from file paths and invokes /system/bin/sh -c. In the CSV-export path, the selected media path is merely surrounded with single quotes; embedded single quotes are not escaped.

Metrics

CVSS Vector: CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
CVSS Score: 8.4

Product Status

Vendor CellHubs
Product ExifTool for photo and video
Versions Default: unaffected
  • Version 5.0.1-gms is affected

Credits

  • Andrés Ramos finder

References

Problem Types

  • CWE-78 Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') CWE

Impacts

  • CAPEC-88 OS Command Injection