CVE-2026-7580

Source
https://cve.org/CVERecord?id=CVE-2026-7580
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-7580.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-7580
Downstream
Published
2026-05-01T12:00:16.465Z
Modified
2026-08-12T03:51:48.733875729Z
Severity
  • 1.9 (Low) CVSS_V4 - CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P CVSS Calculator
Summary
Exiftool JPEG/QuickTime/MOV/MP4 GM.pm Process_mrld code injection
Details

A vulnerability was detected in Exiftool up to 13.53. Impacted is the function Process_mrld of the file lib/Image/ExifTool/GM.pm of the component JPEG/QuickTime/MOV/MP4. The manipulation of the argument -ee results in code injection. Attacking locally is a requirement. Upgrading to version 13.54 is recommended to address this issue. The patch is identified as 5a8b6b6ead12b39e3f32f978a4efd0233facbb01. It is suggested to upgrade the affected component. The fix in the source code mentions: "[J]ust to be safe, probably never happen".

Database specific
{
    "unresolved_ranges": [
        {
            "extracted_events": [
                {
                    "introduced": "13.0"
                },
                {
                    "last_affected": "13.0"
                },
                {
                    "introduced": "13.1"
                },
                {
                    "last_affected": "13.1"
                },
                {
                    "introduced": "13.2"
                },
                {
                    "last_affected": "13.2"
                },
                {
                    "introduced": "13.3"
                },
                {
                    "last_affected": "13.3"
                },
                {
                    "introduced": "13.4"
                },
                {
                    "last_affected": "13.4"
                },
                {
                    "introduced": "13.5"
                },
                {
                    "last_affected": "13.5"
                },
                {
                    "introduced": "13.6"
                },
                {
                    "last_affected": "13.6"
                },
                {
                    "introduced": "13.7"
                },
                {
                    "last_affected": "13.7"
                },
                {
                    "introduced": "13.8"
                },
                {
                    "last_affected": "13.8"
                },
                {
                    "introduced": "13.9"
                },
                {
                    "last_affected": "13.9"
                }
            ],
            "source": "AFFECTED_FIELD"
        }
    ],
    "cna_assigner": "VulDB",
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/7xxx/CVE-2026-7580.json",
    "cwe_ids": [
        "CWE-74",
        "CWE-94"
    ]
}
References

Affected packages

Git / github.com/exiftool/exiftool

Affected ranges

Type
GIT
Repo
https://github.com/exiftool/exiftool
Events
Database specific
Show details
{
    "extracted_events": [
        {
            "introduced": "13.10"
        },
        {
            "last_affected": "13.10"
        },
        {
            "introduced": "13.11"
        },
        {
            "last_affected": "13.11"
        },
        {
            "introduced": "13.12"
        },
        {
            "last_affected": "13.12"
        },
        {
            "introduced": "13.13"
        },
        {
            "last_affected": "13.13"
        },
        {
            "introduced": "13.14"
        },
        {
            "last_affected": "13.14"
        },
        {
            "introduced": "13.15"
        },
        {
            "last_affected": "13.15"
        },
        {
            "introduced": "13.16"
        },
        {
            "last_affected": "13.16"
        },
        {
            "introduced": "13.17"
        },
        {
            "last_affected": "13.17"
        },
        {
            "introduced": "13.18"
        },
        {
            "last_affected": "13.18"
        },
        {
            "introduced": "13.19"
        },
        {
            "last_affected": "13.19"
        },
        {
            "introduced": "13.20"
        },
        {
            "last_affected": "13.20"
        },
        {
            "introduced": "13.21"
        },
        {
            "last_affected": "13.21"
        },
        {
            "introduced": "13.22"
        },
        {
            "last_affected": "13.22"
        },
        {
            "introduced": "13.23"
        },
        {
            "last_affected": "13.23"
        },
        {
            "introduced": "13.24"
        },
        {
            "last_affected": "13.24"
        },
        {
            "introduced": "13.25"
        },
        {
            "last_affected": "13.25"
        },
        {
            "introduced": "13.26"
        },
        {
            "last_affected": "13.26"
        },
        {
            "introduced": "13.27"
        },
        {
            "last_affected": "13.27"
        },
        {
            "introduced": "13.28"
        },
        {
            "last_affected": "13.28"
        },
        {
            "introduced": "13.29"
        },
        {
            "last_affected": "13.29"
        },
        {
            "introduced": "13.30"
        },
        {
            "last_affected": "13.30"
        },
        {
            "introduced": "13.31"
        },
        {
            "last_affected": "13.31"
        },
        {
            "introduced": "13.32"
        },
        {
            "last_affected": "13.32"
        },
        {
            "introduced": "13.33"
        },
        {
            "last_affected": "13.33"
        },
        {
            "introduced": "13.34"
        },
        {
            "last_affected": "13.34"
        },
        {
            "introduced": "13.35"
        },
        {
            "last_affected": "13.35"
        },
        {
            "introduced": "13.36"
        },
        {
            "last_affected": "13.36"
        },
        {
            "introduced": "13.37"
        },
        {
            "last_affected": "13.37"
        },
        {
            "introduced": "13.38"
        },
        {
            "last_affected": "13.38"
        },
        {
            "introduced": "13.39"
        },
        {
            "last_affected": "13.39"
        },
        {
            "introduced": "13.40"
        },
        {
            "last_affected": "13.40"
        },
        {
            "introduced": "13.41"
        },
        {
            "last_affected": "13.41"
        },
        {
            "introduced": "13.42"
        },
        {
            "last_affected": "13.42"
        },
        {
            "introduced": "13.43"
        },
        {
            "last_affected": "13.43"
        },
        {
            "introduced": "13.44"
        },
        {
            "last_affected": "13.44"
        },
        {
            "introduced": "13.45"
        },
        {
            "last_affected": "13.45"
        },
        {
            "introduced": "13.46"
        },
        {
            "last_affected": "13.46"
        },
        {
            "introduced": "13.47"
        },
        {
            "last_affected": "13.47"
        },
        {
            "introduced": "13.48"
        },
        {
            "last_affected": "13.48"
        },
        {
            "introduced": "13.49"
        },
        {
            "last_affected": "13.49"
        },
        {
            "introduced": "13.50"
        },
        {
            "last_affected": "13.50"
        },
        {
            "introduced": "13.51"
        },
        {
            "last_affected": "13.51"
        },
        {
            "introduced": "13.52"
        },
        {
            "last_affected": "13.52"
        },
        {
            "introduced": "13.53"
        },
        {
            "last_affected": "13.53"
        }
    ],
    "source": [
        "AFFECTED_FIELD",
        "REFERENCES"
    ]
}

Affected versions

13.*
13.10
13.11
13.12
13.13
13.14
13.15
13.16
13.17
13.18
13.19
13.20
13.21
13.22
13.23
13.24
13.25
13.26
13.27
13.28
13.29
13.30
13.31
13.32
13.33
13.34
13.35
13.36
13.37
13.38
13.39
13.40
13.41
13.42
13.43
13.44
13.45
13.46
13.47
13.48
13.49
13.50
13.51
13.52
13.53

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-7580.json"