PT-2026-6784 · Go2Rtc+1 · Go2Rtc+1
Jduardo2704
·
Published
2026-02-06
·
Updated
2026-02-06
·
CVE-2026-25643
CVSS v3.1
9.1
Critical
| Vector | AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Frigate versions prior to 0.16.4
Description
Frigate is a network video recorder (NVR) with realtime local object detection for IP cameras. A critical Remote Command Execution (RCE) issue exists in the Frigate integration with go2rtc. The application does not properly sanitize user input within the video stream configuration file (
config.yaml), specifically allowing the injection of system commands through the exec: directive. The go2rtc service then executes these commands without restrictions. This issue is exploitable by an administrator or users who have exposed their Frigate installation to the internet without authentication, potentially granting full administrative control to an attacker.Recommendations
Update Frigate to version 0.16.4 or later.
Exploit
Fix
Improper Privilege Management
OS Command Injection
Exposure of Resource to Wrong Sphere
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Frigate
Go2Rtc