exiftool-vendored is vulnerable to Command Injection
85
High Risk
ExifTool accepted user input for arguments without checking for newlines. If a user included a newline character (\n) in a tag name or filename, ExifTool would treat it as multiple arguments instead of just one. This could allow attackers to inject unexpected commands and cause command injection.
You are affected if you are using a version that falls within the vulnerable range.
exiftool-vendored is vulnerable to Command Injection in versions 30.0.0 - 35.18.0.
Upgrade the exiftool-vendored library to the patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

SOC 2Compliant
ISO 27001Compliant