---
id: CVE-2026-101947
title: >-
  ExifTool for photo and video 5.0.1-gms by CellHubs constructs shell command
  strings from file paths and invokes /system/bin/sh -c
summary: >-
  ExifTool for photo and video 5.0.1-gms by CellHubs constructs shell command
  strings from file paths and invokes /system/bin/sh -c. In the CSV-export path,
  the selected media path is merely surrounded with single quotes; embedded
  single q…
severity: none
cwe:
  - CWE-78
published: '2026-10-10'
updated: '2026-10-10'
sourceUpdated: '2026-10-10T04:18:06.413'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-101947'
references:
  - url: 'https://fluidattacks.com/advisories/saturn'
    label: help@fluidattacks.com
  - url: 'https://play.google.com/store/apps/details?id=com.exiftool.free'
    label: help@fluidattacks.com
tags:
  - nvd
ingestedAt: '2026-10-10T04:21:57.821Z'
---

## Overview

ExifTool for photo and video 5.0.1-gms by CellHubs constructs shell command strings from file paths and invokes /system/bin/sh -c. In the CSV-export path, the selected media path is merely surrounded with single quotes; embedded single quotes are not escaped.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
