Pipecat
Pipecat-AI · 3 CVEs
CVE-2026-54695
HIGH
Pipecat: Telephony WebSocket `/ws` Unauthenticated Call-Control Abuse via Attacker-Supplied Call SID
Jul 9, 2026
CVE-2026-44716
HIGH
Pipecat: Path Traversal in Pipecat Runner `/files` Endpoint — Arbitrary File Read via `%2F`-Encoded Separator
Jun 10, 2026
CVE-2025-62373
CRITICAL
Pipecat vulnerable to Remote Code Execution by Pickle Deserialization via LivekitFrameSerializer
Apr 23, 2026
| CVE ID | Description | Severity | EPSS | Published |
|---|---|---|---|---|
| CVE-2026-54695 | Pipecat: Telephony WebSocket `/ws` Unauthenticated Call-Control Abuse via Attacker-Supplied Call SID | HIGH | 0.56% | Jul 9, 2026 |
| CVE-2026-44716 | Pipecat: Path Traversal in Pipecat Runner `/files` Endpoint — Arbitrary File Read via `%2F`-Encoded Separator | HIGH | 0.56% | Jun 10, 2026 |
| CVE-2025-62373 | Pipecat vulnerable to Remote Code Execution by Pickle Deserialization via LivekitFrameSerializer | CRITICAL | 0.70% | Apr 23, 2026 |
Showing 1 to 3 of 3 CVEs