CVE-2026-3102: exiftool PNG File MacOS.pm SetMacOSTags os command injection
A vulnerability was determined in exiftool up to 13.49 on macOS. This issue affects the function SetMacOSTags of the file lib/Image/ExifTool/MacOS.pm of the component PNG File Parser. This manipulation of the argument DateTimeOriginal causes os command injection. The attack is possible to be carried out remotely. The exploit has been publicly disclosed and may be utilized. Upgrading to version 13.50 is capable of addressing this issue. Patch name: e9609a9bcc0d32bd252a709a562fb822d6dd86f7. Upgrading the affected component is recommended.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2026-3102?
CVE-2026-3102 is classified as a high severity vulnerability due to the potential for remote command execution.
How do I fix CVE-2026-3102?
To fix CVE-2026-3102, update exiftool to version 13.50 or later.
What is the affected software for CVE-2026-3102?
CVE-2026-3102 affects exiftool versions up to and including 13.49 on macOS.
What component is affected by CVE-2026-3102?
CVE-2026-3102 affects the SetMacOSTags function in the PNG File Parser within lib/Image/ExifTool/MacOS.pm.
What type of vulnerability is CVE-2026-3102?
CVE-2026-3102 is an OS command injection vulnerability that allows manipulation of the DateTimeOriginal argument.