CVE-2025-62382 is an information disclosure vulnerability in Frigate NVR versions prior to 0.16.2. An authenticated, low-privilege operator can exploit a flaw in the video export workflow to read arbitrary files from the host system by nominating any filesystem location as a thumbnail source. This vulnerability has a CVSS score of 7.7 (High), indicating a network attack vector with low complexity and high confidentiality impact, allowing exfiltration of sensitive data. Currently, there is no evidence of active exploitation, public exploit code (Metasploit, Nuclei, ExploitDB), or significant community discussion or media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
| Blakeblackshear | Frigate | < 0.16.2CNA affected |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.3 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.