CVE-2026-101947EPSS p3.1%
CVE-2026-101947CVE-2026-101947
Description
ExifTool for photo and video 5.0.1-gms by CellHubs constructs shell command strings from file paths and invokes /system/bin/sh -c. In the CSV-export path, the selected media path is merely surrounded with single quotes; embedded single quotes are not escaped.
Scoring
| EPSS | 0.14% probability of exploitation · percentile 3.1% · 2026-10-10T12:00:23Z |
| Last modified | 2026-10-10 |