CVE-2026-25643 is a remote command execution vulnerability in Frigate's integration with go2rtc affecting versions prior to 0.16.4. According to the provided content, Frigate does not properly sanitize user-controlled input in the video stream configuration (config.yaml). An attacker able to modify stream configuration can inject arbitrary system commands via the go2rtc exec: directive, and the go2rtc service will execute those commands without restriction. The issue is therefore an OS command injection in configuration processing that results in command execution in the context of the Frigate/go2rtc service.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
2 valid exploits after Mallory filtered fakes, detection scripts, and README-only repos (2 hidden).
Repository contains a Python proof-of-concept exploit (CVE-2026-25643.py) for Frigate NVR <= 0.16.3 achieving blind remote command execution by manipulating Frigate’s configuration via its HTTP API. The exploit optionally authenticates to /api/login, fetches the current config from /api/config/raw, injects a malicious go2rtc stream using the 'exec:' directive (exec:bash -c '<cmd>') and a fake camera that references rtsp://127.0.0.1:8554/debug_cmd to trigger stream initialization, then posts the full modified YAML back to /api/config/save?save_option=restart to force a restart/probe where the command executes. No output is captured (blind RCE), and execution may occur multiple times during restart. Repo structure: (1) main exploit script CVE-2026-25643.py (requests + PyYAML) with CLI args for target URL, optional username/password, and command; (2) docker/ directory providing a reproducible vulnerable lab using ghcr.io/blakeblackshear/frigate:0.16.3, exposing ports 5001->5000 (web/API), 1984, 8554, and 8555 TCP/UDP, with auth disabled in config and GO2RTC_ALLOW_ARBITRARY_EXEC=true; (3) documentation files (README/SECURITY/CONTRIBUTING) and requirements.txt. Overall purpose is to demonstrate and test the Frigate config-manipulation RCE fixed in Frigate >= 0.16.4.
Repository purpose: a Python proof-of-concept exploit for CVE-2026-25643 achieving blind RCE against Frigate NVR <= 0.16.3 by manipulating the server configuration. Core exploit (CVE-2026-25643.py): - Uses requests to interact with Frigate’s HTTP API. - Optional authentication via POST /api/login (credentials supplied with -U/-P). If not provided, it attempts unauthenticated access. - Reads the current config from GET /api/config/raw, handling either raw YAML or JSON-wrapped YAML, then parses it with PyYAML. - Injects a malicious go2rtc stream entry: go2rtc.streams.debug_cmd = ["exec:bash -c '<cmd>'"]. - Adds a fake camera (trigger_exec) whose ffmpeg input points to rtsp://127.0.0.1:8554/debug_cmd, causing Frigate/go2rtc to probe the stream. - Submits the modified YAML back to POST /api/config/save?save_option=restart with Content-Type: text/plain, aiming to trigger execution during restart/probe. - Execution is explicitly blind: no output capture, and the command may run multiple times. Notable capabilities: - Arbitrary command execution as the Frigate process user. - Works in both authenticated and (when exposed) unauthenticated scenarios. - No built-in reverse shell handler; user supplies any command (including reverse shells) via -c. Repository structure: - Single exploit script: CVE-2026-25643.py (entry point). - requirements.txt pins requests, PyYAML, urllib3, etc. - Docker PoC environment under docker/: docker-compose.yml runs ghcr.io/blakeblackshear/frigate:0.16.3 with ports exposed and GO2RTC_ALLOW_ARBITRARY_EXEC=true; includes sample config.yml and config.yml.original for restoring state. - Standard project docs: README.md (usage + docker instructions), SECURITY.md, CONTRIBUTING.md, LICENSE.md. Assessment: - This is a real exploit PoC (not just detection). It is operational but basic (blind command execution, minimal automation beyond config injection/restart).
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
12 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A remote code execution vulnerability in Frigate NVR via go2rtc exec injection.
A remote code execution vulnerability in Frigate NVR involving go2rtc exec injection.
A remote code execution vulnerability affecting Frigate NVR via go2rtc exec injection.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.