PT-2025-42390 · Frigate · Frigate
Published
2025-10-15
·
Updated
2025-10-16
·
CVE-2025-62382
CVSS v3.1
7.7
High
| Vector | AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
Frigate versions prior to 0.16.2
Description
Frigate, a network video recorder with real-time object detection for IP cameras, contains a flaw in its export workflow. Before version 0.16.2, an authenticated user could specify any filesystem location as the thumbnail source for video exports. This path is then copied to the publicly accessible clips directory, allowing the reading of arbitrary files on the host system. This allows a low-privilege user with API access to potentially access sensitive configuration files, secrets, or user data. The issue arises from a violation of the principle of least privilege within the export subsystem. The exploitation involves a timing window during file copying before cleanup occurs.
Recommendations
Update to Frigate version 0.16.2 or later.
Exploit
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Frigate