CVE-2026-101947: ExifTool for photo and video 5.0.1 - Local OS command injection through filenames during CSV export
ExifTool for photo and video 5.0.1-gms by CellHubs constructs shell command strings from file paths and invokes /system/bin/sh -c. In the CSV-export path, the selected media path is merely surrounded with single quotes; embedded single quotes are not escaped.