{"id":"CVE-2026-55488","aliases":["GHSA-rw9q-97r9-8gvh","PYSEC-2026-2667"],"url":"https://o3.security/vulnerability/CVE-2026-55488","summary":"motionEye's Absolute Path Traversal in Media File Handlers Allows Arbitrary File Read","details":"### Summary\n\nmEye contains an absolute path traversal vulnerability in multiple media file handlers that allows an attacker to read arbitrary files from the filesystem.\n\nThe affected handlers accept a user-controlled filename parameter and construct filesystem paths using `os.path.join()`. When an absolute path is supplied, Python discards the configured media directory and returns the attacker-supplied path directly. The application then bypasses Tornado's built-in path validation by overriding the relevant safety checks.\n\nAs a result, an attacker can access files outside of the configured camera media directory, subject to the permissions of the motionEye process.\n\n### Details\n\nThe issue exists in the media playback and download functionality.\n\nThe filename parameter is passed to `mediafiles.get_media_path()`:\n\n```python\ndef get_media_path(camera_config, path, media_type):\n    target_dir = camera_config.get('target_dir')\n    full_path = os.path.join(target_dir, path)\n    return full_path\n```\n\nWhen path is an absolute path (e.g. `/etc/motioneye/motion.conf`), Python's `os.path.join()` discards `target_dir` entirely and returns the absolute path as-is. This would normally be caught by Tornado's StaticFileHandler path validation, but MoviePlaybackHandler explicitly overrides both safety checks (`movie_playback.py` lines 111-115):\n\n```\ndef get_absolute_path(self, root, path):\n    return path\n\ndef validate_absolute_path(self, root, absolute_path):\n    return absolute_path\n```\nThis allows reading any file on the filesystem that the motionEye process can access.\n\nThe same path traversal exists in the movie download, picture download, and picture preview handlers:\n\n- GET /movie/<camera_id>/download/<filename>\n- GET /picture/<camera_id>/download/<filename>\n- GET /picture/<camera_id>/preview/<filename>\n\n# PoC\n\n```\nGET /movie/1/playback//etc/motioneye/motion.conf HTTP/1.1\nHost: target:8765\n```\n\n# Fix\n\nDo not allow absolute paths supplied by user input.\n\nValidate that the fully resolved canonical path remains within the configured camera media directory before serving a file.\n\nAdditionally, Tornado’s built-in path validation should not be bypassed unless equivalent validation is performed by motionEye.","published":"2026-06-24T15:03:26.208Z","modified":"2026-08-12T03:51:16.853689393Z","cvss":null,"epss":{"score":0.00623,"percentile":0.47988,"asOf":"2026-09-12"},"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"PyPI","name":"motioneye","fixedVersion":"0.44.0"}],"fix":null,"references":[{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/55xxx/CVE-2026-55488.json"},{"type":"ADVISORY","url":"https://github.com/motioneye-project/motioneye/security/advisories/GHSA-rw9q-97r9-8gvh"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-55488"},{"type":"PACKAGE","url":"https://github.com/motioneye-project/motioneye"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-08-12T03:51:16.853689393Z"}}