Frigate v0.17.2

v0.17.2

0.17.2 Release

Added 1
  • Exports can optionally include recording segment information as chapters in mp4 metadata
Changed 3
  • Performance improvements when displaying previews in the live page
  • Offload preview encoding and Plus upload off the API event loop
  • Allow non-admin users to use PTZ controls for cameras they have access to
Fixed 2
  • Filter motion review by allowed cameras
  • Fix cache control header for current hour preview mp4s
Security 6
  • Fixed go2rtc WebSocket live stream camera access bypass for role-restricted users
  • Fixed incomplete patch of CVE-2025-62382 regarding image_path backslash-separator bypass and arbitrary host-file read
  • Fixed incomplete patch of CVE-2026-25643 regarding go2rtc exec:/echo:/expr: prefix block bypass allowing RCE and container escape
  • Fixed RTSP credentials leak to viewer role via nginx proxy_cache
  • Fixed authenticated admin RCE via go2rtc Stream API by enforcing exec: filter at API layer
  • Fixed WebSocket missing authorization allowing viewer to execute admin-only operations

This is a maintenance release for Frigate 0.17 that includes fixes and minor changes.

Images
What's Changed
Security Advisories

These advisories impact users with publicly exposed instances with no authentication and users with viewer roles where it is important to restrict access to some cameras.

Addressed in this release:

To be addressed in future versions:

Notable Changes
  • Exports can optionally include recording segment information as chapters in mp4 metadata
  • Performance improvements when displaying previews in the live page
All Commits
New Contributors

Full Changelog: https://github.com/blakeblackshear/frigate/compare/v0.17.1...v0.17.2

View original

Upgraded? How did it go?

Discussion