CVE-2026-25643Disclosure(frigate / frigate)

LOWCVSS 9.1 · CRITICAL

Signal is active with 5 mentions in latest observed window

Immediate actions

  • Patch frigate frigate systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

Frigate is a network video recorder (NVR) with realtime local object detection for IP cameras. Prior to 0.16.4, a critical Remote Command Execution (RCE) vulnerability has been identified in the Frigate integration with go2rtc. The application does not sanitize user input in the video stream configuration (config.yaml), allowing direct injection of system commands via the exec: directive. The go2rtc service executes these commands without restrictions. This vulnerability is only exploitable by an administrator or users who have exposed their Frigate install to the open internet with no authentication which allows anyone full administrative control. This vulnerability is fixed in 0.16.4.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-78CWE-250CWE-269CWE-668

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

NONE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • frigate

Threat summary

  • Patch or workaround signal is available
  • 5 mentions across 1 observed day

What's happening

  • Patch or workaround mentioned in 2 signals
  • Technical details provided in 4 signals
  • Disclosure: 3 classified signals
  • General: 1 classified signal
  • 5 total mentions across 1 day

Affected systems

Vendors
Products
frigate

Deep dive

Activity timeline5 mentions / 1d
01345Mentions · 2026-02-06: 5Patch / Workaround · 2026-02-06: 2Technical Details · 2026-02-06: 402-06
Signal classification3 categories
Disclosure
360.0%
General
120.0%
Patch
120.0%
Referenced assets5 URLs
Full discourse5 posts
  • CVEFind.com@CveFindCom
    Disclosure

    [CVE-2026-25643: CRITICAL] Critical RCE vulnerability identified in Frigate integration with go2rtc prior to version 0.16.4. Attackers could exploit this flaw to execute arbitrary commands. Update to the lat...#cve,CVE-2026-25643,#cybersecurity https://cvefind.com/CVE-2026-25643

    Post summary

    A critical RCE vulnerability (CVE-2026-25643) in Frigate integration with go2rtc (pre‑0.16.4) was disclosed; users should apply the update to mitigate the risk.

    0001064
    583 followersView on X
  • The Hacker Wire@TheHackerWire
    Disclosure

    🔴 CVE-2026-25643 - Critical Frigate is a network video recorder (NVR) with realtime local object detection for IP cameras. Prior to 0.16.4, a critical Remote Command Execution (RCE) vulnerability has been identified... https://www.thehackerwire.com/vulnerability/CVE-2026-25643/ https://t.co/FiMTIORO2U

    Post summary

    A critical RCE vulnerability (CVE‑2026‑25643) was discovered in Frigate’s NVR software prior to version 0.16.4, with details referenced in a linked article.

    0000068
    113 followersView on X
  • CVE@CVEnew
    Patch

    CVE-2026-25643 Frigate is a network video recorder (NVR) with realtime local object detection for IP cameras. Prior to 0.16.4, a critical Remote Command Execution (RCE) vulnerabilit… https://www.cve.org/CVERecord?id=CVE-2026-25643

    Post summary

    CVE-2026-25643 is a critical RCE in Frigate NVR before version 0.16.4; updating to that version resolves the issue.

    00000197
    56.5K followersView on X
  • 0day Signal@0dayPublishing
    Disclosure

    🚨 CVE-2026-25643: Frigate Affected by Authenticate... Frigate NVR's go2rtc integration blindly executes unsanitized exec: directives in config.yaml—trivial container escape ... https://zerodaysignal.com/vulnerability/CVE-2026-25643 #netsec #vulnerability #CVE #sysadmin #zeroday

    Post summary

    CVE-2026-25643 enables a trivial container escape in Frigate NVR via unsanitized exec directives in go2rtc config.yaml; no patch, PoC, or active exploitation reported.

    0000076
    132 followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    General

    CVE-2026-25643 CVE-2026-25643 https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-25643

    Post summary

    The text only references CVE-2026-25643 and provides a generic link without detailed information.

    0000076
    4.0K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appfrigatefrigate---

Explore more