PT-2026-36321 · Exiftool · Exiftool

Ilyass-Armadin

·

Published

2026-05-01

·

Updated

2026-05-01

·

CVE-2026-7580

CVSS v3.1

5.3

Medium

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L
Name of the Vulnerable Software and Affected Versions Exiftool versions prior to 13.54
Description Local code injection is possible through the manipulation of the -ee argument. The issue resides in the Process mrld() function within the lib/Image/ExifTool/GM.pm file, specifically affecting the JPEG, QuickTime, MOV, and MP4 components.
Recommendations Upgrade to version 13.54.

Fix

Special Elements Injection

Code Injection

Weakness Enumeration

Related Identifiers

CVE-2026-7580

Affected Products

Exiftool