Frigate is an open-source video surveillance and object-detection platform deployed across home and small-business security installations, where its disclosures have revealed a pattern of authorization and data-handling weaknesses. Vulnerabilities affecting the vendor skew toward serious outcomes and frequently acquire public exploit code, reflecting both the sensitivity of security camera feeds and the platform's exposure to unauthenticated network access. The recurring weakness classes—including incorrect authorization, cross-site request forgery, untrusted deserialization, unnecessary privilege execution, and resource-exposure issues—cluster around authentication boundaries and the handling of user input in a service designed to be accessible over networks. Current severity and exploitation figures are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Frigate over time
Signals from CVEs in this vendor scope (9 CVEs).
9 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2026-25643CRITICAL Frigate is a network video recorder (NVR) with realtime local object detection for IP cameras. Prior to 0.16.4, a critical Remote Command Execution (RCE) vulnerability has been ide | Feb 6, 2026 | 9.1 | 41 | NO | YES |
CVE-2026-33125HIGH Frigate is a network video recorder (NVR) with realtime local object detection for IP cameras. In versions 0.16.2 and below, users with the viewer role can delete admin and low-pri | Mar 20, 2026 | 8.1 | 27 | NO | NO |
CVE-2026-33124HIGH Frigate is a network video recorder (NVR) with realtime local object detection for IP cameras. Versions prior to 0.17.0-beta1 allow any authenticated user to change their own passw | Mar 20, 2026 | 8.8 | 27 | NO | NO |
CVE-2023-45671MEDIUM Frigate is an open source network video recorder. Prior to version 0.13.0 Beta 3, there is a reflected cross-site scripting vulnerability in any API endpoints reliant on the `/<cam | Oct 30, 2023 | 4.7 | 25 | NO | YES |
CVE-2026-33469MEDIUM Frigate is a network video recorder (NVR) with realtime local object detection for IP cameras. In version 0.17.0, an authenticated non-admin user can retrieve the full raw Frigate | Mar 26, 2026 | 6.5 | 22 | NO | NO |
CVE-2023-45672HIGH Frigate is an open source network video recorder. Prior to version 0.13.0 Beta 3, an unsafe deserialization vulnerability was identified in the endpoints used to save configuration | Oct 30, 2023 | 7.5 | 22 | NO | NO |
CVE-2023-45670MEDIUM Frigate is an open source network video recorder. Prior to version 0.13.0 Beta 3, the `config/save` and `config/set` endpoints of Frigate do not implement any CSRF protection. This | Oct 30, 2023 | 6.8 | 20 | NO | NO |
CVE-2026-33470MEDIUM Frigate is a network video recorder (NVR) with realtime local object detection for IP cameras. In version 0.17.0, a low-privilege authenticated user restricted to one camera can ac | Mar 26, 2026 | 4.3 | 18 | NO | NO |
CVE-2026-33126MEDIUM Frigate is a network video recorder (NVR) with realtime local object detection for IP cameras. Prior to version 0.16.3, the /ffprobe endpoint accepts arbitrary user-controlled URLs | Mar 20, 2026 | 4.3 | 18 | NO | NO |
Signals from CVEs in this vendor scope (9 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Frigate.
Media articles that mention a CVE ID that affects a product developed by Frigate — matched by CVE ID, not by vendor name.