Intel

AIKIDO-2026-10638

exiftool-vendored is vulnerable to Command Injection

Command InjectionGHSA-cw26-7653-2rp5 Published Apr 29, 2026

85

High Risk

This Affects:

JSexiftool-vendored
30.0.0 - 35.18.0
Fixed in 35.19.0
Are you affected? Scan for Free

TL;DR

ExifTool accepted user input for arguments without checking for newlines. If a user included a newline character (\n) in a tag name or filename, ExifTool would treat it as multiple arguments instead of just one. This could allow attackers to inject unexpected commands and cause command injection.

Who does this affect?

You are affected if you are using a version that falls within the vulnerable range.

Background info

exiftool-vendored is vulnerable to Command Injection in versions 30.0.0 - 35.18.0.

How to fix this

Upgrade the exiftool-vendored library to the patch version.