{"id":"GHSA-26f6-wm47-7h7j","summary":"Duplicate Advisory: motionEye vulnerable to RCE via unsanitized motion config parameter","details":"## Duplicate Advisory\nThis advisory has been withdrawn because it is a duplicate of GHSA-j945-qm58-4gjx. This link is maintained to preserve external references.\n\n## Original Description\nMotionEye v0.43.1b4 and before is vulnerable to OS Command Injection in configuration parameters such as image_file_name. Unsanitized user input is written to Motion configuration files, allowing remote authenticated attackers with admin access to achieve code execution when Motion is restarted.","modified":"2026-09-10T03:50:29.053641807Z","published":"2025-10-03T18:31:28Z","withdrawn":"2025-11-03T21:47:59Z","database_specific":{"severity":"HIGH","github_reviewed":true,"github_reviewed_at":"2025-11-03T21:47:59Z","nvd_published_at":"2025-10-03T16:16:20Z","cwe_ids":["CWE-20"]},"references":[{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2025-60787"},{"type":"WEB","url":"https://github.com/prabhatverma47/motionEye-RCE-through-config-parameter"},{"type":"WEB","url":"http://motioneye-project.com"}],"affected":[{"package":{"name":"motioneye","ecosystem":"PyPI","purl":"pkg:pypi/motioneye"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"}]}],"versions":["0.27","0.27.1","0.27.2","0.28","0.28.1","0.28.2","0.28.3","0.29","0.29.1","0.29rc1","0.29rc2","0.30","0.30rc1","0.30rc2","0.31","0.31.1","0.31.2","0.31.3","0.31.4","0.31.5","0.32","0.32.1","0.32.2","0.33","0.33.1","0.33.2","0.33.3","0.33.4","0.34","0.34.1","0.34rc1","0.35","0.35.1","0.35.2","0.35rc1","0.36","0.36.1","0.37","0.37.1","0.37rc1","0.38","0.38.1","0.39","0.39.1","0.39.2","0.39.3","0.40","0.40rc1","0.40rc2","0.40rc3","0.40rc4","0.40rc5","0.41","0.41rc1","0.42","0.42.1","0.43.1","0.43.1b1","0.43.1b2","0.43.1b3","0.43.1b4","0.43.1b5","0.44.0","0.44.0b1","0.44.0b2","0.44.0b3"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2025/10/GHSA-26f6-wm47-7h7j/GHSA-26f6-wm47-7h7j.json","last_known_affected_version_range":"\u003c 0.43.1b5"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H"}]}