CVE-2025-60787: Motioneye Project Motioneye

High severity, CVSS 7.2. EPSS: 18.5% chance of exploitation in the next 30 days.

MotionEye v0.43.1b4 and before is vulnerable to OS Command Injection in configuration parameters such as image_file_name. Unsanitized user input is written to Motion configuration files, allowing remote authenticated attackers with admin access to achieve code execution when Motion is restarted.

Affected products

Published 2025-10-03. Last modified 2026-07-05.