MotionEye v0.43.1b4 and before is vulnerable to OS Command Injection in configuration parameters such as image_file_name. Unsanitized user input is written to Motion configuration files, allowing remote authenticated attackers with admin access to achieve code execution when Motion is restarted.
https://github.com/spabam/exploits
https://github.com/Revnin/CCTV-MACHINE
https://github.com/arcovaar3428/Fsociety00_alderson_core.dat
https://github.com/fsoc-ghost-0x/Fsociety00_alderson_core.dat
https://github.com/d3vn0mi/CVE-2025-60787-POC
https://github.com/lil0xplorer/CVE-2025-60787_PoC
https://github.com/h1dr1/CVE_Research
https://github.com/prabhatverma47/motionEye-RCE-through-config-parameter