{"id":"CVE-2025-47782","summary":"motionEye vulnerable to RCE in add_camera Function Due to unsafe command execution","details":"motionEye is an online interface for the software motion, a video surveillance program with motion detection. In versions 0.43.1b1 through 0.43.1b3, using a constructed (camera) device path with the `add`/`add_camera` motionEye web API allows an attacker with motionEye admin user credentials to execute any command within a non-interactive shell as motionEye run user, `motion` by default. The vulnerability has been patched with motionEye v0.43.1b4. As a workaround, apply the patch manually.","aliases":["GHSA-g5mq-prx7-c588","PYSEC-2025-39"],"modified":"2026-08-12T03:51:45.984171305Z","published":"2025-05-14T15:54:59.309Z","database_specific":{"osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2025/47xxx/CVE-2025-47782.json","cna_assigner":"GitHub_M","cwe_ids":["CWE-78"]},"references":[{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2025/47xxx/CVE-2025-47782.json"},{"type":"ADVISORY","url":"https://github.com/motioneye-project/motioneye/security/advisories/GHSA-g5mq-prx7-c588"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2025-47782"},{"type":"REPORT","url":"https://github.com/motioneye-project/motioneye/issues/3142"},{"type":"FIX","url":"https://github.com/motioneye-project/motioneye/pull/3143"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/motioneye-project/motioneye","events":[{"introduced":"2862efef79d9c107379459cea9edbb7bbc3d9161"},{"fixed":"616a5b198f77f97a08f2f2b954dcb1c0428431fb"}],"database_specific":{"extracted_events":[{"introduced":"0.43.1b1"},{"fixed":"0.43.1b4"},{"fixed":"0.43.1b3"}],"source":["AFFECTED_FIELD","DESCRIPTION"]}}],"versions":["0.43.1b3","0.43.1b2","0.43.1b1"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2025-47782.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V4","score":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:P"}]}