ExifTool for photo and video 5.0.1-gms by CellHubs constructs shell command strings from file paths and invokes /system/bin/sh -c. In the CSV-export path, the selected media path is merely surrounded with single quotes; embedded single quotes are not escaped.
Advisories
No advisories yet.
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
Sat, 10 Oct 2026 03:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | ExifTool for photo and video 5.0.1-gms by CellHubs constructs shell command strings from file paths and invokes /system/bin/sh -c. In the CSV-export path, the selected media path is merely surrounded with single quotes; embedded single quotes are not escaped. | |
| Title | ExifTool for photo and video 5.0.1 - Local OS command injection through filenames during CSV export | |
| First Time appeared |
Cellhubs
Cellhubs exiftool For Photo And Video |
|
| Weaknesses | CWE-78 | |
| CPEs | cpe:2.3:a:cellhubs:exiftool_for_photo_and_video:5.0.1-gms:*:android:*:*:*:*:* | |
| Vendors & Products |
Cellhubs
Cellhubs exiftool For Photo And Video |
|
| References |
| |
| Metrics |
cvssV4_0
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: Fluid Attacks
Published:
Updated: 2026-10-10T03:06:42.581Z
Reserved: 2026-09-28T16:24:02.366Z
Link: CVE-2026-101947
No data.
Status : Received
Published: 2026-10-10T04:18:06.413
Modified: 2026-10-10T04:18:06.413
Link: CVE-2026-101947
No data.
OpenCVE Enrichment
No data.
Weaknesses