CVE-2026-101947

CVE-2026-101947 published: ExifTool for photo and video 5.0.1-gms by CellHubs constructs shell command strings from file paths and invokes /system/bin/sh -c. In the CSV-export path, the selected media path is merely surrounded with single quotes; embedded single quotes are not escaped.

View full NVD advisory → ← Back to CVE watch