CVE-2026-3102
exiftool PNG File MacOS.pm SetMacOSTags os command injection
Vexday Risk Score
13Baixo
Decisão SSVC (CISA)
Track
Sem sinal de exploração → monitorar
CVSS 5.3EPSS 3.4%KEV nãoPoC —Nuclei —Metasploit —Patch referenciado
Ciclo de vida
24 fev 2026Publicada no NVD
Recomendação: Monitorar — sem sinal de exploração no momento.
A vulnerability was determined in exiftool up to 13.49 on macOS. This issue affects the function SetMacOSTags of the file lib/Image/ExifTool/MacOS.pm of the component PNG File Parser. This manipulation of the argument DateTimeOriginal causes os command injection. The attack is possible to be carried out remotely. The exploit has been publicly disclosed and may be utilized. Upgrading to version 13.50 is capable of addressing this issue. Patch name: e9609a9bcc0d32bd252a709a562fb822d6dd86f7. Upgrading the affected component is recommended.
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P
Produtos afetados
n/a · exiftoolQuer saber se a sua infraestrutura está exposta a isto?
Falar com a TrueHacking →Referências
https://github.com/exiftool/exiftool/https://github.com/exiftool/exiftool/commit/e9609a9bcc0d32bd252a709a562fb822d6dd86f7https://github.com/exiftool/exiftool/releases/tag/13.50https://vuldb.com/?ctiid.347528https://vuldb.com/?id.347528https://vuldb.com/?submit.758146https://www.youtube.com/watch?v=akk0vmilfb4