CVE-2026-31978 | motioneye-project motioneye up to 0.43.x mediafiles.py get_media_preview filename path traversal (GHSA-g9fx-5r4h-pcw3)
A vulnerability, which was classified as critical, has been found in motioneye-project motioneye up to 0.43.x. The affected element is the function get_media_preview of the file mediafiles.py. The manipulation of the argument filename leads to path traversal.
This vulnerability is uniquely identified as CVE-2026-31978. The attack is possible to be carried out remotely. No exploit exists.
It is advisable to upgrade the affected component.VulDB Recent EntriesRead More