Shell Command Injection Vulnerability in ExifTool by CellHubs
CVE-2026-101947

8.4HIGH

Key Information:

Vendor

Cellhubs

Vendor
CVE Published:
10 October 2026

What is CVE-2026-101947?

ExifTool by CellHubs contains a vulnerability that allows command injection through improperly handled file paths in CSV exports. Specifically, when constructing shell command strings, the media path provided by users is only surrounded by single quotes without proper escaping of embedded single quotes. This oversight may enable an attacker to execute arbitrary commands on the system via crafted media file paths.

Affected Version(s)

ExifTool for photo and video Android 5.0.1-gms

References

CVSS V4

Score:
8.4
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
Unknown

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Andrés Ramos
.