Impact
An unauthorized GET request to the internal go2rtc API endpoint in Frigate allows a user with a viewer role to retrieve sensitive information such as internal addresses, configuration paths, application logs, goroutine stack traces, and RTSP stream URLs that may contain camera credentials. This bypasses the intended administrator‑only restriction and constitutes a privilege‑escalation and information‑disclosure vulnerability (CWE‑863).
Affected Systems
The vulnerability affects Frigate deployments built by blakeblackshear before version 0.18.0. Any instance using a pre‑0.18.0 image is susceptible unless the misconfigured route has been manually secured or disabled.
Risk and Exploitability
The CVSS score of 7.7 indicates a potentially serious risk. While the EPSS score is not available, the simplicity of the bypass—requiring only a logged‑in viewer account—means exploitation is straightforward for an attacker who can obtain or assume such credentials. The vulnerability is not listed in CISA's KEV catalog, so there is no immediate evidence of active exploitation, but the lack of an admin role requirement suggests it could be leveraged by a rogue or compromised user.
OpenCVE Enrichment