A security vulnerability in Frigate video surveillance software allows attackers to execute malicious code on the server by sending specially crafted configuration data through the web interface.
Frigate
Blake Blackshear22.03.2026
Upgrade assessment
SicherheitsrelevantZeitnah aktualisieren
Derived automatically from release, repo and CVE data — no judgment by a language model.
A security vulnerability in Frigate video surveillance software allows cross-site scripting attacks through improper handling of camera names in API endpoints, enabling attackers to execute malicious JavaScript code in user browsers.
Frigate video surveillance software has a vulnerability where attackers can modify server configuration through malicious websites when authenticated users click specially crafted links.
A vulnerability in Frigate video security software allows attackers with access to the application to cause a denial-of-service attack by uploading files with extremely long Unicode names, which overloads the CPU through expensive Unicode normalization processing.
A vulnerability in Frigate video surveillance software allows authenticated users to read arbitrary files from the server by abusing the export function and providing a malicious file path as thumbnail source.
A security vulnerability in Frigate allows attackers to abuse the server to send HTTP requests to internal network resources, as an API endpoint accepts URLs without proper validation.
A vulnerability in Frigate software allows unauthenticated users to delete administrator and other user accounts, potentially causing service disruption and data loss.
Frigate allows authenticated users to change their password without confirming the current password and doesn't invalidate existing sessions. Attackers can permanently take over accounts when sessions are compromised.
A critical security vulnerability in Frigate software allows administrators or attackers on unprotected installations to execute arbitrary system commands through video stream configuration, potentially gaining complete control over the system.
A vulnerability in Frigate software allows authenticated non-admin users to retrieve the complete configuration file containing sensitive data like camera passwords and other secrets through an API endpoint.
A security vulnerability in Frigate software allows authenticated users with restricted camera permissions to view snapshots from other cameras they shouldn't have access to, bypassing access controls.
Maintenance release with security fixes for admin endpoints and cross-camera authentication plus various bug fixes
Frigate 0.17.0 introduces new features including local classification model training, custom viewer roles, and GenAI review summaries with several breaking changes
Security update fixes critical vulnerability for authenticated remote code execution and container escape
Security update fixes critical access control vulnerability and improves recording playback efficiency plus certificate generation
Security update fixes critical vulnerability allowing unauthorized file access via export thumbnail parameter and improves UI performance
Maintenance release with bugfixes for frontend UI, hardware acceleration, autotracking and API endpoints
Frigate 0.16.0 introduces multiple breaking changes including removal of TensorRT detector, audio handling updates, object detection disabled by default, and new authentication requirements
Maintenance release fixes 'too many open files' errors in HAOS 16 by adjusting ulimit settings
Maintenance release with bugfixes for crash in get_current_frame() and TensorRT model preparation script
Frigate 0.15.0 introduces major breaking changes including rewritten SHM system, modified recording configuration, FFmpeg 7 update, and new Explore feature with AI-powered search capabilities
Maintenance release with bugfixes for authentication, iOS export, live player performance and various UI improvements
Frigate 0.14.0 introduces a completely new user interface with significant breaking changes, including incompatible database changes and configuration migration
Maintenance update with improvements to ONVIF handling, Birdseye view, NMS optimizations and various bug fixes
Frigate 0.13.0 fixes critical security vulnerabilities (CSRF, XSS, unsafe deserialization) and removes ARM 32-bit support with database schema changes
Patch release with documentation fixes and increased hash map size for improved performance
Patch release with CPU optimizations for Raspberry Pi hardware acceleration, fixes for recording configuration and UI filters, plus extensive documentation updates
Frigate 0.12.0 introduces multiple breaking changes including migration to GitHub Container Registry, database changes, go2rtc integration, and new detector types
Maintenance update with bug fixes for MQTT labels, motion detection, segment processing and FFprobe handling plus documentation improvements
Frigate 0.11.0 introduces extensive breaking changes with FFmpeg5 upgrade, database migrations, Docker rebuild and new Frigate+ integration for enhanced machine learning
Dynamic contrast made optional and disabled by default, debug print statements removed
Camera names must be URL-safe, new retention modes for recordings, stationary object tracking, and improved motion detection with changed default values
Bug fixes for recording cleanup, configuration validation, and reverting problematic changes from version 0.9.2
Bug fix for prematurely expiring recording segments and switch to mpegts container to reduce video footage loss
Clips merged into recordings, camera configuration structure changed, new recordings viewer and birdseye features added
Frigate 0.9.1 introduces major changes: clips merged into recordings, configuration structure modified, and new viewer features added
Fixes MJPEG stream blocking issues with web server and improves WebUI performance with optimized scrolling
Fixed baseUrl handling for addon ingress and WebSocket connections
Frigate v0.8.2 brings frontend improvements, WebUI switches for features, proactive cache cleanup and new settings for zones and object masks
Frigate v0.8.1 improves FFmpeg logging, fixes Firefox live view issues and optimizes web UI performance