HIGH
CellHubs
CVE published 2026-10-10
CVE-2026-101947
AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-10-10T03:06:42.581Z and has not been modified since then. The vulnerability exists in ExifTool for photo and video 5.0.1-gms, which constructs shell command strings from file paths and invokes /system/bin/sh -c. In the CSV-export path, the selected media path is merely surrounded with single quotes; em [truncated]