Sploitus

CVE-2026-3102

2 known exploits for CVE-2026-3102

A vulnerability was determined in exiftool up to 13.49 on macOS. This issue affects the function SetMacOSTags of the file lib/Image/ExifTool/MacOS.pm of the component PNG File Parser. This manipulation of the argument DateTimeOriginal causes os command injection. The attack is possible to be carried out remotely. The exploit has been publicly disclosed and may be utilized. Upgrading to version 13.50 is capable of addressing this issue. Patch name: e9609a9bcc0d32bd252a709a562fb822d6dd86f7. Upgrading the affected component is recommended.

Affected products
Exiftool
Exiftool Project Exiftool
< 13.50
Fix
Available
CVSS 3.1
8.8 HIGH
EPSS
3.7% (89th percentile)
Weakness
CWE-78, CWE-77
NVD status
Analyzed
Published
2026-02-24
CVE-2026-3102 at NVD
Authoritative description, scoring and affected products

2 known exploits for CVE-2026-3102

Proof-of-concept code and exploit modules indexed by Sploitus