You must log in or register to comment.
“This vulnerability is only exploitable by an administrator or users who have exposed their Frigate install to the open internet with no authentication which allows anyone full administrative control.” High, but not critical
This is why you don’t expose services to the Internet, especially with weak or no authentication.
I’m not sure why anyone would want to expose Frigate of all things to the open internet.
So they could view their cameras while they’re away?
That’s my use case. But my frigate-box is strictly behind firewall and I access it over wireguard when I’m away.
I second this. I have notifications set up via homeassistant, and if I want to view a feed I just VPN in




