{"id":"CVE-2026-55488","title":"motionEye's Absolute Path Traversal in Media File Handlers Allows Arbitrary File Read","summary":"motionEye's Absolute Path Traversal in Media File Handlers Allows Arbitrary File Read","severity":"high","cwe":["CWE-22"],"vendor":"motioneye","product":"motioneye","ecosystem":"pip","affected":["motioneye < 0.44.0"],"patched":["motioneye 0.44.0"],"published":"2026-06-23","updated":"2026-06-23","source":"GHSA","sourceUrl":"https://github.com/advisories/GHSA-rw9q-97r9-8gvh","references":[{"url":"https://github.com/motioneye-project/motioneye/security/advisories/GHSA-rw9q-97r9-8gvh"},{"url":"https://github.com/advisories/GHSA-rw9q-97r9-8gvh"}],"tags":["ghsa","pip"],"epss":0.00623,"epssPercentile":0.48203,"ingestedAt":"2026-06-29T13:24:35.308Z","slug":"CVE-2026-55488","body":"## Overview\n\n### Summary\n\nmEye contains an absolute path traversal vulnerability in multiple media file handlers that allows an attacker to read arbitrary files from the filesystem.\n\nThe affected handlers accept a user-controlled filename parameter and construct filesystem paths using `os.path.join()`. When an absolute path is supplied, Python discards the configured media directory and returns the attacker-supplied path directly. The application then bypasses Tornado's built-in path validation by overriding the relevant safety checks.\n\nAs a result, an attacker can access files outside of the configured camera media directory, subject to the permissions of the motionEye process.\n\n### Details\n\nThe issue exists in the media playback and download functionality.\n\nThe filename parameter is passed to `mediafiles.get_media_path()`:\n\n```python\ndef get_media_path(camera_config, path, media_type):\n    target_dir = camera_config.get('target_dir')\n    full_path = os.path.join(target_dir, path)\n    return full_path\n```\n\nWhen path is an absolute path (e.g. `/etc/motioneye/motion.conf`), Python's `os.path.join()` discards `target_dir` entirely and returns the absolute path as-is. This would normally be caught by Tornado's StaticFileHandler path validation, but MoviePlaybackHandler explicitly overrides both safety checks (`movie_playback.py` lines 111-115):\n\n```\ndef get_absolute_path(self, root, path):\n    return path\n\ndef validate_absolute_path(self, root, absolute_path):\n    return absolute_path\n```\nThis allows reading any file on the filesystem that the motionEye process can access.\n\nThe same path traversal exists in the movie download, picture download, and picture preview handlers:\n\n- GET /movie/<camera_id>/download/<filename>\n- GET /picture/<camera_id>/download/<filename>\n- GET /picture/<camera_id>/preview/<filename>\n\n# PoC\n\n```\nGET /movie/1/playback//etc/motioneye/motion.conf HTTP/1.1\nHost: target:8765\n```\n\n# Fix\n\nDo not allow absolute paths supplied by user input.\n\nValidate that the fully resolved canonical path remains within the configured camera media directory before serving a file.\n\nAdditionally, Tornado’s built-in path validation should not be bypassed unless equivalent validation is performed by motionEye.\n\n## Affected packages\n\n- `motioneye < 0.44.0`\n\n## Remediation\n\nUpgrade to a patched release:\n\n- `motioneye 0.44.0`","depth":"twilight","depthScore":41,"depthScoreParts":{"impact":41.3,"likelihood":0.1,"exploitation":0,"ransomware":0},"changes":[]}