CVE-2026-3102

MEDIUM

exiftool <=13.49 - Command Injection

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2026-3102. PoCs published by HORKimhab.

AI-analyzed exploit summary This repository contains functional exploit code for CVE-2026-3102, targeting ExifTool on macOS. The PoC demonstrates remote code execution via crafted metadata injection in PNG/JPG files, leveraging command injection in the DateTimeOriginal field.

Description

A vulnerability was determined in exiftool up to 13.49 on macOS. This issue affects the function SetMacOSTags of the file lib/Image/ExifTool/MacOS.pm of the component PNG File Parser. This manipulation of the argument DateTimeOriginal causes os command injection. The attack is possible to be carried out remotely. The exploit has been publicly disclosed and may be utilized. Upgrading to version 13.50 is capable of addressing this issue. Patch name: e9609a9bcc0d32bd252a709a562fb822d6dd86f7. Upgrading the affected component is recommended.

Exploits (1)

github WORKING POC 1 stars
by HORKimhab · shellpoc
https://github.com/HORKimhab/CVE-2026-3102

This repository contains functional exploit code for CVE-2026-3102, targeting ExifTool on macOS. The PoC demonstrates remote code execution via crafted metadata injection in PNG/JPG files, leveraging command injection in the DateTimeOriginal field.

Classification
Working Poc 95%
Attack Type
Rce
Complexity
Moderate
Reliability
Reliable
Target: ExifTool ≤ 13.49
No auth needed
Prerequisites: macOS target · ExifTool ≤ 13.49 · attacker-controlled IP/port for reverse shell
devstral-2 · analyzed May 22, 2026 Full analysis →

References (7)

Core 7
Core References
Permissions Required, VDB Entry vdb-entry technical-description
https://vuldb.com/?id.347528
Permissions Required, VDB Entry signature permissions-required
https://vuldb.com/?ctiid.347528
Permissions Required, VDB Entry third-party-advisory
https://vuldb.com/?submit.758146
Various Sources media-coverage
https://www.youtube.com/watch?v=akk0vmilfb4
Various Sources product
https://github.com/exiftool/exiftool/

Scores

CVSS v3 6.3
EPSS 0.0007
EPSS Percentile 22.0%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:L

CISA SSVC

Vulnrichment
Exploitation poc
Automatable no
Technical Impact partial

Details

CWE
CWE-77 CWE-78
Status published
Products (1)
exiftool_project/exiftool < 13.50
Published Feb 24, 2026
Tracked Since Feb 24, 2026