Frigate is a network video recorder (NVR) with realtime local object detection for IP cameras. Prior to 0.16.4, a critical Remote Command Execution (RCE) vulnerability has been identified in the Frigate integration with go2rtc. The application does not sanitize user input in the video stream configuration (config.yaml), allowing direct injection of system commands via the exec: directive. The go2rtc service executes these commands without restrictions. This vulnerability is only exploitable by an administrator or users who have exposed their Frigate install to the open internet with no authentication which allows anyone full administrative control. This vulnerability is fixed in 0.16.4.
Conclusion & alert: CVE-2026-25643 is rated High Exploit Risk (82.7/100): CVSS Critical severity, with medium exploitation likelihood (EPSS 2.87%). Core evidence: 2 public exploit reference(s) are indexed (Exploit-DB). EPSS rose +1.61% over the last day, indicating growing attacker interest. Mandatory action: Public exploits are available—assess exposure, apply mitigations, and prioritize patching.
Risk is dynamic; we continuously reassess and refresh what is shown on this page as upstream context changes.
| EDB-ID | Source | Kind | Published | Link |
|---|---|---|---|---|
| 52533 | exploit_db | edb | 2026-04-30 | Exploit-DB ↗ |
| — | nvd_ref | exploit_tag | Exploit-DB ↗ |
EPSS lead: Daily EPSS estimates relative likelihood of exploitation; percentile ranks this CVE among scored vulnerabilities (higher = more severe relative rank).
| # | Date | Old EPSS score | New EPSS score | Delta (New - Old) |
|---|---|---|---|---|
| 1 | 2026-06-15 | 1.26% | 2.87% | +1.61% |
| 2 | 2026-05-01 | 0.37% | 1.26% | +0.90% |
| 3 | 2026-03-20 | — | 0.37% | — |
Full EPSS history (6 records total)
CVSS metrics for this CVE.
| Base score | Version | Severity | Vector | Exploitability | Impact | Score source |
|---|---|---|---|---|---|---|
| 9.1 | 3.1 | CRITICAL |
|
2.3 | 6.0 | [email protected] |
| URL | Tags |
|---|---|
| https://github.com/blakeblackshear/frigate/releases/tag/v0.16.4 | Release Notes |
| https://github.com/blakeblackshear/frigate/security/advisories/GHSA-4c97-5jmr-8f6x | Exploit Vendor Advisory |