CVE-2026-43893 affects exiftool-vendored, a package that provides cross-platform Node.js access to ExifTool. In versions prior to 35.19.0, the package launches ExifTool in '-stay_open True -@ -' mode, where ExifTool reads arguments from standard input one line at a time. Several caller-controlled strings were interpolated into ExifTool arguments without rejecting newline or carriage return characters. As a result, an attacker-controlled line delimiter could terminate the intended argument and inject additional ExifTool arguments. The fix also rejects NUL bytes as unsafe control characters. This is an argument injection flaw rather than demonstrated remote code execution.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
1 valid exploit after Mallory filtered fakes, detection scripts, and README-only repos.
This repository is a minimal proof-of-concept exploit set for a vulnerability in exiftool-vendored.js. It contains only three files: a README linking to the upstream security advisory and two JavaScript PoCs. Both scripts import exiftool from the exiftool-vendored package and call exiftool.write() with maliciously crafted metadata tag names containing embedded newlines. The apparent purpose is to show that unsafely handled tag keys can be transformed into additional ExifTool command-line arguments. poc1.js demonstrates arbitrary file write/path manipulation by injecting the -o option and specifying ../exploit as the destination, indicating write outside the expected directory. poc2.js demonstrates local file disclosure by injecting an execute block with -p /etc/passwd and -w! leak.txt, causing contents of a local file to be written into leak.txt. There is no network communication, persistence, or post-exploitation logic; the repository is strictly a local PoC showing exploitability and impact. The code is short, hardcoded, and intended for demonstration rather than operational use.
4 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.