VYPR

Motioneye

by Motioneye Project

pypi: motioneye

Source repositories

CVEs (9)

  • CVE-2026-46488criJun 22, 2026
    risk 0.59cvss epss

    ### Summary An authentication bypass vulnerability exists due to improper trust in client-controlled cookies. The application accepts user-supplied cookie values containing a username and password-hash-derived value as sufficient authentication material. These cookies can be set…

  • CVE-2025-60787HigOct 3, 2025
    risk 0.52cvss 7.2epss 0.18

    MotionEye v0.43.1b4 and before is vulnerable to OS Command Injection in configuration parameters such as image_file_name. Unsanitized user input is written to Motion configuration files, allowing remote authenticated attackers with admin access to achieve code execution when…

  • CVE-2025-47782HigMay 14, 2025
    risk 0.51cvss epss 0.00

    motionEye is an online interface for the software motion, a video surveillance program with motion detection. In versions 0.43.1b1 through 0.43.1b3, using a constructed (camera) device path with the `add`/`add_camera` motionEye web API allows an attacker with motionEye admin…

  • CVE-2021-44255HigJan 31, 2022
    risk 0.47cvss 7.2epss 0.03

    Authenticated remote code execution in MotionEye <= 0.42.1 and MotioneEyeOS <= 20200606 allows a remote attacker to upload a configuration backup file containing a malicious python pickle file which will execute arbitrary code on the server.

  • CVE-2026-31978MedJun 24, 2026
    risk 0.42cvss 6.5epss 0.00

    motionEye (mEye) is an online interface for motion software, which is a video surveillance program with motion detection. Versions prior to 0.44.0 are vulnerable to path traversal in the picture and movie API endpoints, suhc as /picture/{id}/preview/{filename}. Neither the API…

  • CVE-2022-25568HigMar 24, 2022
    risk 0.42cvss 7.5epss 0.07

    MotionEye v0.42.1 and below allows attackers to access sensitive information via a GET request to /config/list. To exploit this vulnerability, a regular user password must be unconfigured.

  • CVE-2026-55488HigJun 24, 2026
    risk 0.39cvss epss 0.01

    motionEye (mEye) is an online interface for a piece of software called "motion," which is a video surveillance program with motion detection. Versions prior to 0.44.0 contain an absolute path traversal vulnerability in multiple media file handlers that allows an attacker to read…

  • CVE-2026-32315MedJun 24, 2026
    risk 0.36cvss 5.5epss 0.01

    motionEye (mEye) is an online interface for motion software, a video surveillance program with motion detection. Versions prior to 0.44.0 create the configuration file /etc/motioneye/motion.conf with 644 permissions (-rw-r--r--), making it readable by any local user on the…

  • CVE-2026-55863medJun 23, 2026
    risk 0.26cvss epss

    ## Summary The `ActionHandler.post()` method in motionEye has no authentication decorator, allowing any unauthenticated attacker to trigger camera actions including snapshots, recording start/stop, and configured action scripts (PTZ controls, alarm triggers, etc.). ##…