CVE-2025-60787
High · CVSS 7.2motioneye — OS Command Injection via unsanitized configuration parameter write (CWE-20, CWE-78, CWE-116)
- CVSS
- 7.2
- nvd
- EPSS
- —
- KEV
- No
- Class
- oss containerizable
- CWE-20, CWE-78, CWE-116
Description
MotionEye v0.43.1b4 and before is vulnerable to OS Command Injection in configuration parameters such as image_file_name. Unsanitized user input is written to Motion configuration files, allowing remote authenticated attackers with admin access to achieve code execution when Motion is restarted.
Search profile — drives PoC discovery
Symbols image_file_namemotion configuration filesMotion restartconfig parametermotioneye config write
Keywords CVE-2025-60787motioneye RCEmotioneye OS command injectionmotioneye image_file_name exploitmotioneye config parameter injectionmotionEye-RCE-through-config-parametermotioneye v0.43.1b4 vulnerabilitymotioneye authenticated RCE
Versions: <=0.43.1b4
Ranked PoCs (9) — best first
Heuristic ranking — not yet expert-vetted. Scored on structure + provenance, not execution.
- ★ 0
- ★ 10gunzf0x/CVE-2025-60787 needs reviewgh_search · Python
- ★ 2lil0xplorer/CVE-2025-60787_PoC needs reviewgh_search · Python
- ★ 1Rohitberiwala/CVE-2025-60787-MotionEye-RCE needs reviewgh_search · Python
- ★ 0gh_search · YARA
- ★ 0agent-skywalker/CVE-2025-60787 needs reviewgh_search · Python
- ★ 0d3vn0mi/CVE-2025-60787-POC needs reviewgh_search · Python
- ★ 0fkie-cad/nvd-json-data-feeds needs reviewtrickest
- ★ 0prabhatverma47/CVE-2025-60787 needs reviewgh_search
Recall-favoring discovery; ranking by the Stage-4 scorer (Adam's rubric). Scanner/aggregator repos are hidden.
Affected packages
| PyPI | motioneye | 0 → 0.43.1b5 |
References
Status: enriched · ingested 2026-07-05T06:00:39.000Z · profiled 2026-07-06T06:30:39.000Z