Aller au contenu principal
CRITICAL

CVE-2026-25643

Frigate Affected by Authenticated Remote Command Execution (RCE) and Container Escape

CVSS v3

9.1

CRITICAL

Score EPSS

1.3 %

probabilité d’exploitation

CISA KEV

Non

exploitation connue

Exploitation

poc

statut SSVC

Description

Frigate is a network video recorder (NVR) with realtime local object detection for IP cameras. Prior to 0.16.4, a critical Remote Command Execution (RCE) vulnerability has been identified in the Frigate integration with go2rtc. The application does not sanitize user input in the video stream configuration (config.yaml), allowing direct injection of system commands via the exec: directive. The go2rtc service executes these commands without restrictions. This vulnerability is only exploitable by a

Détails techniques

Vecteur CVSS v3
3.1
Publiée le
2026-02-06
Dernière modification
2026-02-11
Exploit-DB
EDB-52533

Questions fréquentes

Qu’est-ce que CVE-2026-25643 ?

Frigate is a network video recorder (NVR) with realtime local object detection for IP cameras. Prior to 0.16.4, a critical Remote Command Execution (RCE) vulnerability has been identified in the Frigate integration with go2rtc. The application does not sanitize user input in the video stream configuration (config.yaml), allowing direct injection of system commands via the exec: directive. The go2rtc service executes these commands without restrictions. This vulnerability is only exploitable by a

CVE-2026-25643 est-elle activement exploitée ?

Une preuve de concept existe pour CVE-2026-25643, mais aucune exploitation active n’est confirmée à ce jour.

Quel est le score CVSS de CVE-2026-25643 ?

CVE-2026-25643 a un score de base CVSS v3 de 9.1 (gravité CRITICAL), avec le vecteur 3.1.

CVE-2026-25643 touche-t-elle votre environnement ?

Utilisez isMalicious pour vérifier si l’une de vos IP ou l’un de vos domaines est associé aux IOC de cette vulnérabilité.

Sans carte bancaire · 500 vérifications gratuites par mois · Clé API gratuite