Generated remediation guidance and an executive summary. No account required.
A vulnerability was determined in exiftool up to 13.49 on macOS. This issue affects the function SetMacOSTags of the file lib/Image/ExifTool/MacOS.pm of the component PNG File Parser. This manipulation of the argument DateTimeOriginal causes os command injection. The attack is possible to be carried out remotely. The exploit has been publicly disclosed and may be utilized. Upgrading to version 13.50 is capable of addressing this issue. Patch name: e9609a9bcc0d32bd252a709a562fb822d6dd86f7. Upgrading the affected component is recommended.
Use CWE-77, Exiftool Project vendor hub and Exiftool product page to widen CVE-2026-3102 into its surrounding weakness, vendor, and product context.
Compare it with CVE-2021-22204, CVE-2022-23935 and CVE-2018-20211 for nearby disclosures in the same product family.