Shell Command Injection Vulnerability in ExifTool by CellHubs
CVE-2026-101947
8.4HIGH
What is CVE-2026-101947?
ExifTool by CellHubs contains a vulnerability that allows command injection through improperly handled file paths in CSV exports. Specifically, when constructing shell command strings, the media path provided by users is only surrounded by single quotes without proper escaping of embedded single quotes. This oversight may enable an attacker to execute arbitrary commands on the system via crafted media file paths.
Affected Version(s)
ExifTool for photo and video Android 5.0.1-gms
