CVE Wiki Pixee · CVE intelligence
← All CVEs

CVE-2025-60787

High · CVSS 7.2

motioneye — OS Command Injection via unsanitized configuration parameter write (CWE-20, CWE-78, CWE-116)

CVSS
7.2
nvd
EPSS
KEV
No
Class
oss containerizable
CWE-20, CWE-78, CWE-116

Description

MotionEye v0.43.1b4 and before is vulnerable to OS Command Injection in configuration parameters such as image_file_name. Unsanitized user input is written to Motion configuration files, allowing remote authenticated attackers with admin access to achieve code execution when Motion is restarted.

Search profile — drives PoC discovery

Symbols image_file_namemotion configuration filesMotion restartconfig parametermotioneye config write
Keywords CVE-2025-60787motioneye RCEmotioneye OS command injectionmotioneye image_file_name exploitmotioneye config parameter injectionmotionEye-RCE-through-config-parametermotioneye v0.43.1b4 vulnerabilitymotioneye authenticated RCE
Versions: <=0.43.1b4

Ranked PoCs (9) — best first

Heuristic ranking — not yet expert-vetted. Scored on structure + provenance, not execution.

Recall-favoring discovery; ranking by the Stage-4 scorer (Adam's rubric). Scanner/aggregator repos are hidden.

Affected packages

PyPI motioneye 0 → 0.43.1b5

References

Status: enriched · ingested 2026-07-05T06:00:39.000Z · profiled 2026-07-06T06:30:39.000Z