{"id":"CVE-2025-47782","aliases":["GHSA-g5mq-prx7-c588","PYSEC-2025-39"],"url":"https://o3.security/vulnerability/CVE-2025-47782","summary":"motionEye vulnerable to RCE in add_camera Function Due to unsafe command execution","details":"motionEye is an online interface for the software motion, a video surveillance program with motion detection. In versions 0.43.1b1 through 0.43.1b3, using a constructed (camera) device path with the `add`/`add_camera` motionEye web API allows an attacker with motionEye admin user credentials to execute any command within a non-interactive shell as motionEye run user, `motion` by default. The vulnerability has been patched with motionEye v0.43.1b4. As a workaround, apply the patch manually.","published":"2025-05-14T15:54:59.309Z","modified":"2026-08-08T03:48:15.349120148Z","cvss":null,"epss":null,"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"PyPI","name":"motioneye","fixedVersion":"0.43.1b4"}],"fix":{"url":"https://github.com/motioneye-project/motioneye/pull/3143","label":"motioneye-project/motioneye#3143"},"references":[{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2025/47xxx/CVE-2025-47782.json"},{"type":"ADVISORY","url":"https://github.com/motioneye-project/motioneye/security/advisories/GHSA-g5mq-prx7-c588"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2025-47782"},{"type":"REPORT","url":"https://github.com/motioneye-project/motioneye/issues/3142"},{"type":"FIX","url":"https://github.com/motioneye-project/motioneye/pull/3143"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-08-08T03:48:15.349120148Z"}}