Exiftool Project maintains a utility for reading and writing metadata across a wide range of image and media file formats, and its attack surface centers on the parsing and interpretation of untrusted file structures. The recurring weakness classes in its disclosure profile reflect the inherent risks of command-line tools that process and transform file metadata: OS command injection, code injection, and improper handling of search paths represent the core exposures where file-driven input can escape its intended parsing scope and flow into system execution contexts. Current exploitation activity and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Exiftool Project over time
Signals from CVEs in this vendor scope (4 CVEs).
4 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2021-22204HIGH Improper neutralization of user data in the DjVu file format in ExifTool versions 7.44 and up allows arbitrary code execution when parsing the malicious image | Apr 23, 2021 | 7.8 | 98 | YES | YES |
CVE-2026-3102HIGH A vulnerability was determined in exiftool up to 13.49 on macOS. This issue affects the function SetMacOSTags of the file lib/Image/ExifTool/MacOS.pm of the component PNG File Pars | Feb 24, 2026 | 8.8 | 37 | NO | NO |
CVE-2022-23935HIGH lib/Image/ExifTool.pm in ExifTool before 12.38 mishandles a $file =~ /\|$/ check, leading to command injection. | Jan 25, 2022 | 7.8 | 29 | NO | NO |
CVE-2018-20211HIGH ExifTool 8.32 allows local users to gain privileges by creating a %TEMP%\par-%username%\cache-exiftool-8.32 folder with a victim's username, and then copying a Trojan horse ws32_32 | Jan 2, 2019 | 7.8 | 25 | NO | NO |
Signals from CVEs in this vendor scope (4 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Exiftool Project.
Media articles that mention a CVE ID that affects a product developed by Exiftool Project — matched by CVE ID, not by vendor name.