PT-2026-6784 · Go2Rtc+1 · Go2Rtc+1

Jduardo2704

·

Published

2026-02-06

·

Updated

2026-02-06

·

CVE-2026-25643

CVSS v3.1

9.1

Critical

VectorAV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Frigate versions prior to 0.16.4
Description Frigate is a network video recorder (NVR) with realtime local object detection for IP cameras. A critical Remote Command Execution (RCE) issue exists in the Frigate integration with go2rtc. The application does not properly sanitize user input within the video stream configuration file (config.yaml), specifically allowing the injection of system commands through the exec: directive. The go2rtc service then executes these commands without restrictions. This issue is exploitable by an administrator or users who have exposed their Frigate installation to the internet without authentication, potentially granting full administrative control to an attacker.
Recommendations Update Frigate to version 0.16.4 or later.

Exploit

Fix

Improper Privilege Management

OS Command Injection

Exposure of Resource to Wrong Sphere

Weakness Enumeration

Related Identifiers

CVE-2026-25643
GHSA-4C97-5JMR-8F6X

Affected Products

Frigate
Go2Rtc