Description
ExifTool for photo and video 5.0.1-gms by CellHubs constructs shell command strings from file paths and invokes /system/bin/sh -c. In the CSV-export path, the selected media path is merely surrounded with single quotes; embedded single quotes are not escaped.
Analysis and contextual insights are available on OpenCVE Cloud.
Remediation
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
Advisories
No advisories yet.
References
History
Sat, 10 Oct 2026 03:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | ExifTool for photo and video 5.0.1-gms by CellHubs constructs shell command strings from file paths and invokes /system/bin/sh -c. In the CSV-export path, the selected media path is merely surrounded with single quotes; embedded single quotes are not escaped. | |
| Title | ExifTool for photo and video 5.0.1 - Local OS command injection through filenames during CSV export | |
| First Time appeared |
Cellhubs
Cellhubs exiftool For Photo And Video |
|
| Weaknesses | CWE-78 | |
| CPEs | cpe:2.3:a:cellhubs:exiftool_for_photo_and_video:5.0.1-gms:*:android:*:*:*:*:* | |
| Vendors & Products |
Cellhubs
Cellhubs exiftool For Photo And Video |
|
| References |
| |
| Metrics |
cvssV4_0
|
Status: PUBLISHED
Assigner: Fluid Attacks
Published:
Updated: 2026-10-10T03:06:42.581Z
Reserved: 2026-09-28T16:24:02.366Z
Link: CVE-2026-101947
No data.
No data.
No data.
OpenCVE Enrichment
No data.
Weaknesses