Josh HawkinsandGitHub 7786da465f Check export thumbnail image access (#24603)
* require export image_path to belong to the exported camera

image_path was only checked for containment under the clips directory, which every camera shares, so a user restricted to one camera could start an export of that camera and have the server copy another camera's image, or a file from an admin-only directory like faces, into the export thumbnail. The path now also has to resolve to the camera being exported, using the same classifier that gates media requests.

* check image_path against the caller's read access instead of the exported camera

Requiring the image to belong to the exported camera rejected custom images that a script saves under the clips directory for its own export pipeline. The path is now accepted whenever the caller's role could read it as media, so admins and unrestricted roles can use any image there and restricted roles are limited to their own cameras.
2026-10-09 07:34:55 -06:00
2026-07-25 11:22:05 -06:00
2026-03-20 07:24:34 -06:00
2026-10-05 11:26:08 -06:00
2021-02-25 07:01:59 -06:00
2026-07-08 08:27:38 -05:00
2026-07-25 11:22:05 -06:00
2026-05-20 08:36:49 -06:00
2026-07-25 11:22:05 -06:00
2023-01-06 07:03:16 -06:00
2026-01-01 09:56:09 -06:00
2023-11-18 08:04:43 -06:00
2026-07-06 12:28:02 -05:00

logo

Frigate NVR™ - Realtime Object Detection for IP Cameras

License: MIT

Translation status

[English] | 简体中文

A complete and local NVR designed for Home Assistant with AI object detection. Uses OpenCV and Tensorflow to perform realtime object detection locally for IP cameras.

Use of a GPU or AI accelerator is highly recommended. AI accelerators will outperform even the best CPUs with very little overhead. See Frigate's supported object detectors.

  • Tight integration with Home Assistant via a custom component
  • Designed to minimize resource use and maximize performance by only looking for objects when and where it is necessary
  • Leverages multiprocessing heavily with an emphasis on realtime over processing every frame
  • Uses a very low overhead motion detection to determine where to run object detection
  • Object detection with TensorFlow runs in separate processes for maximum FPS
  • Communicates over MQTT for easy integration into other systems
  • Records video with retention settings based on detected objects
  • 24/7 recording
  • Re-streaming via RTSP to reduce the number of connections to your camera
  • WebRTC & MSE support for low-latency live view

Documentation

View the documentation at https://docs.frigate.video

Donations

If you would like to make a donation to support development, please use Github Sponsors.

License

This project is licensed under the MIT License.

  • Code: The source code, configuration files, and documentation in this repository are available under the MIT License. You are free to use, modify, and distribute the code as long as you include the original copyright notice.
  • Trademarks: The "Frigate" name, the "Frigate NVR" brand, and the Frigate logo are trademarks of Frigate, Inc. and are not covered by the MIT License.

Please see our Trademark Policy for details on acceptable use of our brand assets.

Screenshots

Live dashboard

Live dashboard

Streamlined review workflow

Streamlined review workflow

Multi-camera scrubbing

Multi-camera scrubbing

Built-in mask and zone editor

Built-in mask and zone editor

Translations

We use Weblate to support language translations. Contributions are always welcome.

Translation status

Copyright © 2026 Frigate, Inc.

Languages
Python 49.5%
TypeScript 49.1%
Shell 0.5%
CSS 0.3%
Dockerfile 0.2%
Other 0.2%