CVE-2026-43893 - exiftool-vendored: Argument injection via newline characters in tag names
CVE ID :CVE-2026-43893 Published : May 11, 2026, 10:22 p.m. | 43 minutes ago Description :exiftool-vendored provides cross-platform Node.js access to ExifTool. Prior to 35.19.0, exiftool-vendored starts ExifTool in -stay_open True -@ - mode, where arguments are read from stdin one per line. In
ORIGINAL SOURCE →via CVE Feed Latest
ADVERTISEMENT
⚡ STAY AHEAD
Events like this, convergence-verified across 689 sources, land in your inbox every Sunday. Free.
GET THE SUNDAY BRIEFING →RELATED · cyber
- [CYBER] Google Detects First AI-Generated Zero-Day Exploit
- [CYBER] Privacy watchdog wraps up probe into Coupang data leak, to decide penalty as early as June
- [CYBER] Pressure mounts on Canvas as data leak extortion deadline looms
- [CYBER] Developer of education tool Canvas issues apology after hack
- [CYBER] Double Canvas breach acknowledged as ShinyHunters sets new pay-or-leak deadline
- [CYBER] Nvidia GeForce NOW data breach confirmed — but luckily most of us will be safe, here's why