Monitor vulnerabilities like this one. Sign up free to get alerted when software you use is affected.
5.3

Exiftool on macOS allows attackers to run malicious commands

CVE-2026-3102
Summary

A security issue in exiftool on macOS allows attackers to execute system commands by manipulating certain file data. This could potentially be exploited remotely. Upgrading to version 13.50 is recommended to fix this issue.

What to do

No fix is available yet. Check with your software vendor for updates.

Affected software
VendorProductAffected versionsFix available
exiftool_project exiftool <= 13.50 –
Original title
A vulnerability was determined in exiftool up to 13.49 on macOS. This issue affects the function SetMacOSTags of the file lib/Image/ExifTool/MacOS.pm of the component PNG File Parser. This manipula...
Original description
A vulnerability was determined in exiftool up to 13.49 on macOS. This issue affects the function SetMacOSTags of the file lib/Image/ExifTool/MacOS.pm of the component PNG File Parser. This manipulation of the argument DateTimeOriginal causes os command injection. The attack is possible to be carried out remotely. The exploit has been publicly disclosed and may be utilized. Upgrading to version 13.50 is capable of addressing this issue. Patch name: e9609a9bcc0d32bd252a709a562fb822d6dd86f7. Upgrading the affected component is recommended.
nvd CVSS2.0 7.5
nvd CVSS3.1 8.8
nvd CVSS4.0 5.3
Vulnerability type
CWE-77 Command Injection
CWE-78 OS Command Injection
Published: 24 Feb 2026 · Updated: 12 Mar 2026 · First seen: 6 Mar 2026