CVE-2025-60787: Motioneye Project Motioneye
High severity, CVSS 7.2. EPSS: 18.5% chance of exploitation in the next 30 days.
MotionEye v0.43.1b4 and before is vulnerable to OS Command Injection in configuration parameters such as image_file_name. Unsanitized user input is written to Motion configuration files, allowing remote authenticated attackers with admin access to achieve code execution when Motion is restarted.
Affected products
- Motioneye Project Motioneye: version 0.42.1 only; version 0.43.1 only
Published 2025-10-03. Last modified 2026-07-05.