CVE-2026-101947: Cellhubs Exiftool For Photo And Video
High severity, CVSS 8.4. EPSS: 0.1% chance of exploitation in the next 30 days.
ExifTool for photo and video 5.0.1-gms by CellHubs constructs shell command strings from file paths and invokes /system/bin/sh -c. In the CSV-export path, the selected media path is merely surrounded with single quotes; embedded single quotes are not escaped.
Affected products
- Cellhubs Exiftool For Photo And Video: version 5.0.1-gms only
Published 2026-10-10. Last modified 2026-10-10.