{"id":"PYSEC-2025-39","details":"motionEye is an online interface for the software motion, a video surveillance program with motion detection. In versions 0.43.1b1 through 0.43.1b3, using a constructed (camera) device path with the `add`/`add_camera` motionEye web API allows an attacker with motionEye admin user credentials to execute any command within a non-interactive shell as motionEye run user, `motion` by default. The vulnerability has been patched with motionEye v0.43.1b4. As a workaround, apply the patch manually.","aliases":["CVE-2025-47782","GHSA-g5mq-prx7-c588"],"modified":"2025-05-14T17:57:10.936625Z","published":"2025-05-14T16:15:29Z","references":[{"type":"ADVISORY","url":"https://github.com/motioneye-project/motioneye/security/advisories/GHSA-g5mq-prx7-c588"},{"type":"REPORT","url":"https://github.com/motioneye-project/motioneye/issues/3142"},{"type":"WEB","url":"https://github.com/motioneye-project/motioneye/pull/3143"}],"affected":[{"package":{"name":"motioneye","ecosystem":"PyPI","purl":"pkg:pypi/motioneye"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0.43.1b1"},{"fixed":"0.43.1b4"}]}],"versions":["0.43.1b1","0.43.1b2","0.43.1b3"],"database_specific":{"source":"https://github.com/pypa/advisory-database/blob/main/vulns/motioneye/PYSEC-2025-39.yaml"}}],"schema_version":"1.7.3"}