motioneye vulnerabilities
CVEs whose affected-version data names the motioneye package (pip). Each record lists the affected and patched versions; check a specific version with the dependency checker or POST /api/sbom.
10 CVEsRSS
CVE-2026-46488Critical· 9.1PoCmotionEye (mEye) is an online interface for a piece of software called "motion," which is a video surveillance program with motion detection
motionEye (mEye) is an online interface for a piece of software called "motion," which is a video surveillance program with motion detection. Prior to 0.44.0, motionEye accepts the client-controlled meye_username and meye_password_hash c…
CVE-2026-55863Medium· 5.3PoCmotionEye (mEye) is an online interface for a piece of software called "motion," which is a video surveillance program with motion detection
motionEye (mEye) is an online interface for a piece of software called "motion," which is a video surveillance program with motion detection. Prior to 0.44.0, the ActionHandler.post() method in motioneye/handlers/action.py lacks the Base…
CVE-2026-55488HighmotionEye's Absolute Path Traversal in Media File Handlers Allows Arbitrary File Read
motionEye's Absolute Path Traversal in Media File Handlers Allows Arbitrary File Read
GHSA-qxvg-h7q2-hcxhCritical· 9.8motionEye: LFI → pass‑the‑hash admin → unsafe restore → unauth action exec (RCE)
motionEye: LFI → pass‑the‑hash admin → unsafe restore → unauth action exec (RCE)
GHSA-phv5-334h-mxcwCriticalmotionEye Partial Authentication Bypass: Unauthenticated Admin Credential Theft via Path Traversal
motionEye Partial Authentication Bypass: Unauthenticated Admin Credential Theft via Path Traversal
CVE-2026-31978Medium· 6.5motionEye has an Arbitrary File Read via Path Traversal in Picture/Movie Preview Endpoint
motionEye has an Arbitrary File Read via Path Traversal in Picture/Movie Preview Endpoint
CVE-2026-32315Medium· 5.5motionEye's World-Readable Configuration File Exposes Admin Password Hash
motionEye's World-Readable Configuration File Exposes Admin Password Hash
CVE-2025-60787High· 7.2PoCmotionEye vulnerable to RCE via unsanitized motion config parameter
motionEye vulnerable to RCE via unsanitized motion config parameter
CVE-2025-47782HighmotionEye vulnerable to RCE in add_camera Function Due to unsafe command execution
motionEye vulnerable to RCE in add_camera Function Due to unsafe command execution
CVE-2021-44255High· 7.2PoCUnrestricted Upload of File with Dangerous Type in motionEye
Unrestricted Upload of File with Dangerous Type in motionEye