Executive brief
The exiftool-vendored library, used for reading and writing metadata in images and videos, is vulnerable to a security flaw where an attacker can inject unauthorized commands. By including special characters like newlines in file names or metadata tags, an attacker could force the application to read sensitive files or overwrite data on the server. This could lead to unauthorized data access or disruption of file integrity.
Technical details
The exiftool-vendored library is vulnerable to argument injection (CWE-88) because it fails to properly sanitize line delimiters when passing arguments to the underlying ExifTool process running in '-stay_open' mode. In this mode, ExifTool reads arguments from stdin one per line; by injecting newline (\n) or carriage return (\r) characters into tag names, filenames, or certain options, an attacker can split a single intended argument into multiple commands. This allows an attacker to read arbitrary files or write output to unauthorized filesystem paths accessible to the process. The vulnerability is fixed in version 35.19.0, which introduces strict tag-name validation and a defense-in-depth check in the command renderer to reject control characters.
Affected products
- photostructure exiftool-vendored <= 35.18.0
Timeline
- 2026-04-25: disclosed: Vulnerability reported by Hank Tam
- 2026-05-05: advisory: GitHub Advisory published
- 2026-05-11: patched: Fix released in version 35.19.0