PT-2025-42390 · Frigate · Frigate

Published

2025-10-15

·

Updated

2025-10-16

·

CVE-2025-62382

CVSS v3.1

7.7

High

VectorAV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions Frigate versions prior to 0.16.2
Description Frigate, a network video recorder with real-time object detection for IP cameras, contains a flaw in its export workflow. Before version 0.16.2, an authenticated user could specify any filesystem location as the thumbnail source for video exports. This path is then copied to the publicly accessible clips directory, allowing the reading of arbitrary files on the host system. This allows a low-privilege user with API access to potentially access sensitive configuration files, secrets, or user data. The issue arises from a violation of the principle of least privilege within the export subsystem. The exploitation involves a timing window during file copying before cleanup occurs.
Recommendations Update to Frigate version 0.16.2 or later.

Exploit

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2025-62382
GHSA-8GV4-5JR9-V96J

Affected Products

Frigate