frigate
Security Risk Profile
Security Risk Score
Comprehensive risk assessment based on 16 vulnerabilities, EPSS scores, exploitation status, and remediation availability.
📅 Data spans from October 30, 2023 to present
Threat Assessment
Severity Distribution
Exploit Likelihood
Age Distribution
Common Weaknesses (CWE)
Most Affected Products
Recent Vulnerabilities
See more →Frigate: Viewer-Role User Can Access go2rtc Internal API to obtain sensitive information
Frigate: WebSocket Missing Authorization — Viewer Can Execute Admin-Only Operations
Frigate viewer can read logs exposing admin and camera credentials
Frigate has cross-camera snapshot disclosure via unrestricted timeline IDs and missing authorization in /api/events/{event_id}/snapshot-clean.webp
Authenticated Frigate users can read the full unredacted configuration via `/api/config/raw
Frigate has SSRF vulnerability in /ffprobe endpoint
Frigate has insecure password change functionality
Frigate Broken Access Control: Users assigned the viewer role can delete admin and other low-privileged accounts
Frigate Affected by Authenticated Remote Command Execution (RCE) and Container Escape
Frigate 3.36.0.9 - 'Command Line' Local Buffer Overflow
Monitor frigate in Real-Time
Get instant alerts when new vulnerabilities are discovered. Stay ahead of security threats with SecAlerts.