CVE-2026-101947: Cellhubs Exiftool For Photo And Video

High severity, CVSS 8.4. EPSS: 0.1% chance of exploitation in the next 30 days.

ExifTool for photo and video 5.0.1-gms by CellHubs constructs shell command strings from file paths and invokes /system/bin/sh -c. In the CSV-export path, the selected media path is merely surrounded with single quotes; embedded single quotes are not escaped.

Affected products

  • Cellhubs Exiftool For Photo And Video: version 5.0.1-gms only

Published 2026-10-10. Last modified 2026-10-10.