CVE-2025-62382

7.7

Frigate · Network Video Recorder (NVR)

Frigate NVR versions prior to 0.16.2 contain an arbitrary file read vulnerability allowing authenticated operators to access sensitive host files via the export workflow.

Executive summary

A critical vulnerability in Frigate NVR allows an authenticated user to perform arbitrary file reads, potentially leading to the exposure of sensitive system secrets and configuration data.

Vulnerability

The vulnerability is caused by improper validation of file paths within the export workflow, which allows an authenticated operator to specify arbitrary filesystem locations as thumbnail sources. This flaw, classified as CWE-73, permits a low-privilege authenticated attacker to exfiltrate sensitive files from the host machine by manipulating the export process.

Business impact

The ability for an attacker to read arbitrary files from the underlying host poses a significant risk to the confidentiality of the entire appliance. Successful exploitation could result in the compromise of API keys, database credentials, or system configuration files, providing an attacker with the necessary information to escalate privileges or gain persistent unauthorized access to the network infrastructure. With a CVSS score of 7.7, this vulnerability represents a high-severity risk that demands immediate attention to prevent lateral movement or total system compromise.

Remediation

Immediate Action: Update the Frigate NVR software to version 0.16.2 or later, which contains the necessary path validation fixes to prevent arbitrary file access.

Proactive Monitoring: Review system and application logs for unusual export activity or requests targeting system-level configuration files that fall outside expected video storage directories.

Compensating Controls: Restrict access to the Frigate API to trusted users only and implement network segmentation to ensure that the NVR appliance is not reachable from untrusted network segments.

Exploitation status

Public Exploit Available: No (unknown)

Analyst recommendation

Given the high-severity nature of this information disclosure flaw, organizations currently running Frigate NVR must prioritize patching to version 0.16.2. The risk of exposing sensitive host secrets is substantial, and the existence of a proof-of-concept increases the likelihood of exploitation by malicious actors. Administrators should apply the update during the next available maintenance window to effectively neutralize this threat.

More Frigate CVEs

Sources

Originally found and disclosed by demforce - Enrico Masala, per the CVE Program record.