pipecat-ai
Open Source framework for voice agents, multimodal apps, and realtime AI. Maintained by Daily and the community.
Activity
- Latest release
- 2d ago
- Total releases
- 113
- Cadence
- ~7 days
- Last 12 months
- 35
Reach
- Stars
- 15.5k
Details
- License
- BSD-2-Clause
- First release
- May 13, 2024
| Version | Released | |
|---|---|---|
1.10.0
minor
| ||
1.9.0
minor
| ||
1.8.1
patch
| ||
1.8.0
minor
| ||
1.7.0
minor
| ||
1.6.0
minor
| ||
1.5.0
minor
| ||
1.4.0
minor
| ||
1.3.0
minor
1 CVE
CVE-2026-54695
PYSEC-2026-2878
GHSA-j8cv-x86q-rj85
Jul 13, 2026
Pipecat: Telephony WebSocket `/ws` Unauthenticated Call-Control Abuse via Attacker-Supplied Call SID
7.5
/ 10
High
Network
High
None
None
Changed
None
Low
High
Development Runner Telephony WebSocket
| ||
1.2.1
patch
1 CVE
CVE-2026-54695
PYSEC-2026-2878
GHSA-j8cv-x86q-rj85
Jul 13, 2026
Pipecat: Telephony WebSocket `/ws` Unauthenticated Call-Control Abuse via Attacker-Supplied Call SID
7.5
/ 10
High
Network
High
None
None
Changed
None
Low
High
Development Runner Telephony WebSocket
| ||
1.2.0
minor
1 CVE
CVE-2026-54695
PYSEC-2026-2878
GHSA-j8cv-x86q-rj85
Jul 13, 2026
Pipecat: Telephony WebSocket `/ws` Unauthenticated Call-Control Abuse via Attacker-Supplied Call SID
7.5
/ 10
High
Network
High
None
None
Changed
None
Low
High
Development Runner Telephony WebSocket
| ||
1.1.0
minor
2 CVEs
CVE-2026-54695
PYSEC-2026-2878
GHSA-j8cv-x86q-rj85
Jul 13, 2026
Pipecat: Telephony WebSocket `/ws` Unauthenticated Call-Control Abuse via Attacker-Supplied Call SID
7.5
/ 10
High
Network
High
None
None
Changed
None
Low
High
Development Runner Telephony WebSocket
| ||
1.0.0
major
2 CVEs
CVE-2026-54695
PYSEC-2026-2878
GHSA-j8cv-x86q-rj85
Jul 13, 2026
Pipecat: Telephony WebSocket `/ws` Unauthenticated Call-Control Abuse via Attacker-Supplied Call SID
7.5
/ 10
High
Network
High
None
None
Changed
None
Low
High
Development Runner Telephony WebSocket
| ||
0.0.108
patch
2 CVEs
CVE-2026-54695
PYSEC-2026-2878
GHSA-j8cv-x86q-rj85
Jul 13, 2026
Pipecat: Telephony WebSocket `/ws` Unauthenticated Call-Control Abuse via Attacker-Supplied Call SID
7.5
/ 10
High
Network
High
None
None
Changed
None
Low
High
Development Runner Telephony WebSocket
| ||
0.0.107
patch
2 CVEs
CVE-2026-54695
PYSEC-2026-2878
GHSA-j8cv-x86q-rj85
Jul 13, 2026
Pipecat: Telephony WebSocket `/ws` Unauthenticated Call-Control Abuse via Attacker-Supplied Call SID
7.5
/ 10
High
Network
High
None
None
Changed
None
Low
High
Development Runner Telephony WebSocket
| ||
0.0.106
patch
2 CVEs
CVE-2026-54695
PYSEC-2026-2878
GHSA-j8cv-x86q-rj85
Jul 13, 2026
Pipecat: Telephony WebSocket `/ws` Unauthenticated Call-Control Abuse via Attacker-Supplied Call SID
7.5
/ 10
High
Network
High
None
None
Changed
None
Low
High
Development Runner Telephony WebSocket
| ||
0.0.105
patch
2 CVEs
CVE-2026-54695
PYSEC-2026-2878
GHSA-j8cv-x86q-rj85
Jul 13, 2026
Pipecat: Telephony WebSocket `/ws` Unauthenticated Call-Control Abuse via Attacker-Supplied Call SID
7.5
/ 10
High
Network
High
None
None
Changed
None
Low
High
Development Runner Telephony WebSocket
| ||
0.0.104
patch
2 CVEs
CVE-2026-54695
PYSEC-2026-2878
GHSA-j8cv-x86q-rj85
Jul 13, 2026
Pipecat: Telephony WebSocket `/ws` Unauthenticated Call-Control Abuse via Attacker-Supplied Call SID
7.5
/ 10
High
Network
High
None
None
Changed
None
Low
High
Development Runner Telephony WebSocket
| ||
0.0.103
patch
2 CVEs
CVE-2026-54695
PYSEC-2026-2878
GHSA-j8cv-x86q-rj85
Jul 13, 2026
Pipecat: Telephony WebSocket `/ws` Unauthenticated Call-Control Abuse via Attacker-Supplied Call SID
7.5
/ 10
High
Network
High
None
None
Changed
None
Low
High
Development Runner Telephony WebSocket
| ||
0.0.102
patch
2 CVEs
CVE-2026-54695
PYSEC-2026-2878
GHSA-j8cv-x86q-rj85
Jul 13, 2026
Pipecat: Telephony WebSocket `/ws` Unauthenticated Call-Control Abuse via Attacker-Supplied Call SID
7.5
/ 10
High
Network
High
None
None
Changed
None
Low
High
Development Runner Telephony WebSocket
| ||
0.0.101
patch
2 CVEs
CVE-2026-54695
PYSEC-2026-2878
GHSA-j8cv-x86q-rj85
Jul 13, 2026
Pipecat: Telephony WebSocket `/ws` Unauthenticated Call-Control Abuse via Attacker-Supplied Call SID
7.5
/ 10
High
Network
High
None
None
Changed
None
Low
High
Development Runner Telephony WebSocket
| ||
0.0.100
patch
2 CVEs
CVE-2026-54695
PYSEC-2026-2878
GHSA-j8cv-x86q-rj85
Jul 13, 2026
Pipecat: Telephony WebSocket `/ws` Unauthenticated Call-Control Abuse via Attacker-Supplied Call SID
7.5
/ 10
High
Network
High
None
None
Changed
None
Low
High
Development Runner Telephony WebSocket
| ||
0.0.99
patch
2 CVEs
CVE-2026-54695
PYSEC-2026-2878
GHSA-j8cv-x86q-rj85
Jul 13, 2026
Pipecat: Telephony WebSocket `/ws` Unauthenticated Call-Control Abuse via Attacker-Supplied Call SID
7.5
/ 10
High
Network
High
None
None
Changed
None
Low
High
Development Runner Telephony WebSocket
| ||
0.0.98
patch
2 CVEs
CVE-2026-54695
PYSEC-2026-2878
GHSA-j8cv-x86q-rj85
Jul 13, 2026
Pipecat: Telephony WebSocket `/ws` Unauthenticated Call-Control Abuse via Attacker-Supplied Call SID
7.5
/ 10
High
Network
High
None
None
Changed
None
Low
High
Development Runner Telephony WebSocket
| ||
0.0.97
patch
2 CVEs
CVE-2026-54695
PYSEC-2026-2878
GHSA-j8cv-x86q-rj85
Jul 13, 2026
Pipecat: Telephony WebSocket `/ws` Unauthenticated Call-Control Abuse via Attacker-Supplied Call SID
7.5
/ 10
High
Network
High
None
None
Changed
None
Low
High
Development Runner Telephony WebSocket
| ||
0.0.96
patch
2 CVEs
CVE-2026-54695
PYSEC-2026-2878
GHSA-j8cv-x86q-rj85
Jul 13, 2026
Pipecat: Telephony WebSocket `/ws` Unauthenticated Call-Control Abuse via Attacker-Supplied Call SID
7.5
/ 10
High
Network
High
None
None
Changed
None
Low
High
Development Runner Telephony WebSocket
| ||
0.0.95
patch
2 CVEs
CVE-2026-54695
PYSEC-2026-2878
GHSA-j8cv-x86q-rj85
Jul 13, 2026
Pipecat: Telephony WebSocket `/ws` Unauthenticated Call-Control Abuse via Attacker-Supplied Call SID
7.5
/ 10
High
Network
High
None
None
Changed
None
Low
High
Development Runner Telephony WebSocket
| ||
0.0.94
patch
2 CVEs
CVE-2026-54695
PYSEC-2026-2878
GHSA-j8cv-x86q-rj85
Jul 13, 2026
Pipecat: Telephony WebSocket `/ws` Unauthenticated Call-Control Abuse via Attacker-Supplied Call SID
7.5
/ 10
High
Network
High
None
None
Changed
None
Low
High
Development Runner Telephony WebSocket
| ||
0.0.93
patch
3 CVEs
CVE-2026-54695
PYSEC-2026-2878
GHSA-j8cv-x86q-rj85
Jul 13, 2026
Pipecat: Telephony WebSocket `/ws` Unauthenticated Call-Control Abuse via Attacker-Supplied Call SID
7.5
/ 10
High
Network
High
None
None
Changed
None
Low
High
Development Runner Telephony WebSocket
| ||
0.0.92
patch
3 CVEs
CVE-2026-54695
PYSEC-2026-2878
GHSA-j8cv-x86q-rj85
Jul 13, 2026
Pipecat: Telephony WebSocket `/ws` Unauthenticated Call-Control Abuse via Attacker-Supplied Call SID
7.5
/ 10
High
Network
High
None
None
Changed
None
Low
High
Development Runner Telephony WebSocket
| ||
0.0.91
patch
3 CVEs
CVE-2026-54695
PYSEC-2026-2878
GHSA-j8cv-x86q-rj85
Jul 13, 2026
Pipecat: Telephony WebSocket `/ws` Unauthenticated Call-Control Abuse via Attacker-Supplied Call SID
7.5
/ 10
High
Network
High
None
None
Changed
None
Low
High
Development Runner Telephony WebSocket
| ||
0.0.90
patch
3 CVEs
CVE-2026-54695
PYSEC-2026-2878
GHSA-j8cv-x86q-rj85
Jul 13, 2026
Pipecat: Telephony WebSocket `/ws` Unauthenticated Call-Control Abuse via Attacker-Supplied Call SID
7.5
/ 10
High
Network
High
None
None
Changed
None
Low
High
Development Runner Telephony WebSocket
| ||
0.0.89
patch
2 CVEs
CVE-2026-54695
PYSEC-2026-2878
GHSA-j8cv-x86q-rj85
Jul 13, 2026
Pipecat: Telephony WebSocket `/ws` Unauthenticated Call-Control Abuse via Attacker-Supplied Call SID
7.5
/ 10
High
Network
High
None
None
Changed
None
Low
High
Development Runner Telephony WebSocket
| ||
0.0.88
patch
2 CVEs
CVE-2026-54695
PYSEC-2026-2878
GHSA-j8cv-x86q-rj85
Jul 13, 2026
Pipecat: Telephony WebSocket `/ws` Unauthenticated Call-Control Abuse via Attacker-Supplied Call SID
7.5
/ 10
High
Network
High
None
None
Changed
None
Low
High
Development Runner Telephony WebSocket
| ||
0.0.87
patch
2 CVEs
CVE-2026-54695
PYSEC-2026-2878
GHSA-j8cv-x86q-rj85
Jul 13, 2026
Pipecat: Telephony WebSocket `/ws` Unauthenticated Call-Control Abuse via Attacker-Supplied Call SID
7.5
/ 10
High
Network
High
None
None
Changed
None
Low
High
Development Runner Telephony WebSocket
| ||
0.0.86
patch
2 CVEs
CVE-2026-54695
PYSEC-2026-2878
GHSA-j8cv-x86q-rj85
Jul 13, 2026
Pipecat: Telephony WebSocket `/ws` Unauthenticated Call-Control Abuse via Attacker-Supplied Call SID
7.5
/ 10
High
Network
High
None
None
Changed
None
Low
High
Development Runner Telephony WebSocket
| ||
0.0.85
patch
2 CVEs
CVE-2026-54695
PYSEC-2026-2878
GHSA-j8cv-x86q-rj85
Jul 13, 2026
Pipecat: Telephony WebSocket `/ws` Unauthenticated Call-Control Abuse via Attacker-Supplied Call SID
7.5
/ 10
High
Network
High
None
None
Changed
None
Low
High
Development Runner Telephony WebSocket
| ||
0.0.84
patch
2 CVEs
CVE-2026-54695
PYSEC-2026-2878
GHSA-j8cv-x86q-rj85
Jul 13, 2026
Pipecat: Telephony WebSocket `/ws` Unauthenticated Call-Control Abuse via Attacker-Supplied Call SID
7.5
/ 10
High
Network
High
None
None
Changed
None
Low
High
Development Runner Telephony WebSocket
| ||
0.0.83
patch
2 CVEs
CVE-2026-54695
PYSEC-2026-2878
GHSA-j8cv-x86q-rj85
Jul 13, 2026
Pipecat: Telephony WebSocket `/ws` Unauthenticated Call-Control Abuse via Attacker-Supplied Call SID
7.5
/ 10
High
Network
High
None
None
Changed
None
Low
High
Development Runner Telephony WebSocket
| ||
0.0.82
patch
2 CVEs
CVE-2026-54695
PYSEC-2026-2878
GHSA-j8cv-x86q-rj85
Jul 13, 2026
Pipecat: Telephony WebSocket `/ws` Unauthenticated Call-Control Abuse via Attacker-Supplied Call SID
7.5
/ 10
High
Network
High
None
None
Changed
None
Low
High
Development Runner Telephony WebSocket
|
0.0.82
patch
Dependencies (70)
+ 62 more
Changelog
Compare changes
|
|
0.0.81
patch
2 CVEs
CVE-2026-54695
PYSEC-2026-2878
GHSA-j8cv-x86q-rj85
Jul 13, 2026
Pipecat: Telephony WebSocket `/ws` Unauthenticated Call-Control Abuse via Attacker-Supplied Call SID
7.5
/ 10
High
Network
High
None
None
Changed
None
Low
High
Development Runner Telephony WebSocket
|
0.0.81
patch
Dependencies (70)
+ 62 more
Changelog
Compare changes
|
|
0.0.80
patch
2 CVEs
CVE-2026-54695
PYSEC-2026-2878
GHSA-j8cv-x86q-rj85
Jul 13, 2026
Pipecat: Telephony WebSocket `/ws` Unauthenticated Call-Control Abuse via Attacker-Supplied Call SID
7.5
/ 10
High
Network
High
None
None
Changed
None
Low
High
Development Runner Telephony WebSocket
|
0.0.80
patch
Dependencies (69)
+ 61 more
Changelog
Compare changes
|
|
0.0.79
patch
2 CVEs
CVE-2026-54695
PYSEC-2026-2878
GHSA-j8cv-x86q-rj85
Jul 13, 2026
Pipecat: Telephony WebSocket `/ws` Unauthenticated Call-Control Abuse via Attacker-Supplied Call SID
7.5
/ 10
High
Network
High
None
None
Changed
None
Low
High
Development Runner Telephony WebSocket
|
0.0.79
patch
Dependencies (67)
+ 59 more
Changelog
Compare changes
|
|
0.0.78
patch
2 CVEs
CVE-2026-54695
PYSEC-2026-2878
GHSA-j8cv-x86q-rj85
Jul 13, 2026
Pipecat: Telephony WebSocket `/ws` Unauthenticated Call-Control Abuse via Attacker-Supplied Call SID
7.5
/ 10
High
Network
High
None
None
Changed
None
Low
High
Development Runner Telephony WebSocket
|
0.0.78
patch
Dependencies (67)
+ 59 more
Changelog
Compare changes
|
|
0.0.77
patch
2 CVEs
CVE-2026-54695
PYSEC-2026-2878
GHSA-j8cv-x86q-rj85
Jul 13, 2026
Pipecat: Telephony WebSocket `/ws` Unauthenticated Call-Control Abuse via Attacker-Supplied Call SID
7.5
/ 10
High
Network
High
None
None
Changed
None
Low
High
Development Runner Telephony WebSocket
|
0.0.77
patch
Dependencies (68)
+ 60 more
Changelog
Compare changes
|
|
0.0.76
patch
1 CVE
CVE-2025-62373
PYSEC-2026-458
GHSA-c2jg-5cp7-6wc7
Jun 29, 2026
Pipecat: Remote Code Execution by Pickle Deserialization Through LivekitFrameSerializer
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
Remote Code Execution via Unsafe Deserialization in Pipecat's LivekitFrameSerializer SummaryA critical vulnerability exists in Pipecat's DetailsThe Vulnerable code in src/pipecat/serializers/livekit.py:
Python's In summary, whenever Proof of Concept (PoC)The following proof-of-concept demonstrates how an attacker could exploit this vulnerability. It involves two steps: (1) running a Pipecat WebSocket server using the vulnerable serializer, and (2) sending a malicious pickle from a client. Start a Pipecat WebSocket server with the LivekitFrameSerializer enabled – for example, by binding the server to all network interfaces (0.0.0.0) on port 8765. In a Pipecat application, this might be done by specifying the LiveKit serializer in the WebSocket transport parameters. For illustration, the code snippet below starts a server:
In this setup, the server listens on ws://0.0.0.0:8765 (with a default path of /ws for WebSocket connections). It will use Send a malicious pickle payload from a client – an attacker can now connect to the WebSocket and transmit a crafted pickle object that executes code. For instance, the payload below defines a class RCE whose
ImpactIf an application uses It's important to note that by default Pipecat does not use LivekitFrameSerializer (and in fact the class is deprecated), so only systems that explicitly opt into this serializer are affected. However, because the class exists in the codebase, users might inadvertently use it. Any such usage on a public-facing or even internal network service can be exploited by an attacker with network access to the service. The worst-case scenario is an internet-exposed Pipecat server using this serializer, which would allow remote exploitation by anyone with access to the WebSocket port. MitigationUsers of Pipecat should take the following actions to eliminate or reduce the risk of this vulnerability:
In summary, the best mitigation is to stop using the vulnerable LivekitFrameSerializer altogether. If users require LiveKit functionality, upgrade to the latest Pipecat version and switch to the recommended Affected versions
0.0.41
0.0.42
0.0.43
0.0.44
0.0.45
0.0.46
0.0.47
0.0.48
0.0.49
0.0.50
0.0.51
0.0.52
+ 41 more Show less
0.0.53
0.0.54
0.0.55
0.0.56
0.0.57
0.0.58
0.0.59
0.0.60
0.0.61
0.0.62
0.0.63
0.0.64
0.0.65
0.0.66
0.0.67
0.0.68
0.0.69
0.0.70
0.0.71
0.0.72
0.0.73
0.0.74
0.0.75
0.0.76
0.0.77
0.0.78
0.0.79
0.0.80
0.0.81
0.0.82
0.0.83
0.0.84
0.0.85
0.0.86
0.0.87
0.0.88
0.0.89
0.0.90
0.0.91
0.0.92
0.0.93
Fixed in
0.0.94
References
Updated Jul 01, 2026 · Source: OSV.dev |
0.0.76
patch
Dependencies (64)
+ 56 more
Changelog
Compare changes
|
|
0.0.75
patch
1 CVE
CVE-2025-62373
PYSEC-2026-458
GHSA-c2jg-5cp7-6wc7
Jun 29, 2026
Pipecat: Remote Code Execution by Pickle Deserialization Through LivekitFrameSerializer
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
Remote Code Execution via Unsafe Deserialization in Pipecat's LivekitFrameSerializer SummaryA critical vulnerability exists in Pipecat's DetailsThe Vulnerable code in src/pipecat/serializers/livekit.py:
Python's In summary, whenever Proof of Concept (PoC)The following proof-of-concept demonstrates how an attacker could exploit this vulnerability. It involves two steps: (1) running a Pipecat WebSocket server using the vulnerable serializer, and (2) sending a malicious pickle from a client. Start a Pipecat WebSocket server with the LivekitFrameSerializer enabled – for example, by binding the server to all network interfaces (0.0.0.0) on port 8765. In a Pipecat application, this might be done by specifying the LiveKit serializer in the WebSocket transport parameters. For illustration, the code snippet below starts a server:
In this setup, the server listens on ws://0.0.0.0:8765 (with a default path of /ws for WebSocket connections). It will use Send a malicious pickle payload from a client – an attacker can now connect to the WebSocket and transmit a crafted pickle object that executes code. For instance, the payload below defines a class RCE whose
ImpactIf an application uses It's important to note that by default Pipecat does not use LivekitFrameSerializer (and in fact the class is deprecated), so only systems that explicitly opt into this serializer are affected. However, because the class exists in the codebase, users might inadvertently use it. Any such usage on a public-facing or even internal network service can be exploited by an attacker with network access to the service. The worst-case scenario is an internet-exposed Pipecat server using this serializer, which would allow remote exploitation by anyone with access to the WebSocket port. MitigationUsers of Pipecat should take the following actions to eliminate or reduce the risk of this vulnerability:
In summary, the best mitigation is to stop using the vulnerable LivekitFrameSerializer altogether. If users require LiveKit functionality, upgrade to the latest Pipecat version and switch to the recommended Affected versions
0.0.41
0.0.42
0.0.43
0.0.44
0.0.45
0.0.46
0.0.47
0.0.48
0.0.49
0.0.50
0.0.51
0.0.52
+ 41 more Show less
0.0.53
0.0.54
0.0.55
0.0.56
0.0.57
0.0.58
0.0.59
0.0.60
0.0.61
0.0.62
0.0.63
0.0.64
0.0.65
0.0.66
0.0.67
0.0.68
0.0.69
0.0.70
0.0.71
0.0.72
0.0.73
0.0.74
0.0.75
0.0.76
0.0.77
0.0.78
0.0.79
0.0.80
0.0.81
0.0.82
0.0.83
0.0.84
0.0.85
0.0.86
0.0.87
0.0.88
0.0.89
0.0.90
0.0.91
0.0.92
0.0.93
Fixed in
0.0.94
References
Updated Jul 01, 2026 · Source: OSV.dev |
0.0.75
patch
Dependencies (64)
+ 56 more
Changelog
Compare changes
|
|
0.0.74
patch
1 CVE
CVE-2025-62373
PYSEC-2026-458
GHSA-c2jg-5cp7-6wc7
Jun 29, 2026
Pipecat: Remote Code Execution by Pickle Deserialization Through LivekitFrameSerializer
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
Remote Code Execution via Unsafe Deserialization in Pipecat's LivekitFrameSerializer SummaryA critical vulnerability exists in Pipecat's DetailsThe Vulnerable code in src/pipecat/serializers/livekit.py:
Python's In summary, whenever Proof of Concept (PoC)The following proof-of-concept demonstrates how an attacker could exploit this vulnerability. It involves two steps: (1) running a Pipecat WebSocket server using the vulnerable serializer, and (2) sending a malicious pickle from a client. Start a Pipecat WebSocket server with the LivekitFrameSerializer enabled – for example, by binding the server to all network interfaces (0.0.0.0) on port 8765. In a Pipecat application, this might be done by specifying the LiveKit serializer in the WebSocket transport parameters. For illustration, the code snippet below starts a server:
In this setup, the server listens on ws://0.0.0.0:8765 (with a default path of /ws for WebSocket connections). It will use Send a malicious pickle payload from a client – an attacker can now connect to the WebSocket and transmit a crafted pickle object that executes code. For instance, the payload below defines a class RCE whose
ImpactIf an application uses It's important to note that by default Pipecat does not use LivekitFrameSerializer (and in fact the class is deprecated), so only systems that explicitly opt into this serializer are affected. However, because the class exists in the codebase, users might inadvertently use it. Any such usage on a public-facing or even internal network service can be exploited by an attacker with network access to the service. The worst-case scenario is an internet-exposed Pipecat server using this serializer, which would allow remote exploitation by anyone with access to the WebSocket port. MitigationUsers of Pipecat should take the following actions to eliminate or reduce the risk of this vulnerability:
In summary, the best mitigation is to stop using the vulnerable LivekitFrameSerializer altogether. If users require LiveKit functionality, upgrade to the latest Pipecat version and switch to the recommended Affected versions
0.0.41
0.0.42
0.0.43
0.0.44
0.0.45
0.0.46
0.0.47
0.0.48
0.0.49
0.0.50
0.0.51
0.0.52
+ 41 more Show less
0.0.53
0.0.54
0.0.55
0.0.56
0.0.57
0.0.58
0.0.59
0.0.60
0.0.61
0.0.62
0.0.63
0.0.64
0.0.65
0.0.66
0.0.67
0.0.68
0.0.69
0.0.70
0.0.71
0.0.72
0.0.73
0.0.74
0.0.75
0.0.76
0.0.77
0.0.78
0.0.79
0.0.80
0.0.81
0.0.82
0.0.83
0.0.84
0.0.85
0.0.86
0.0.87
0.0.88
0.0.89
0.0.90
0.0.91
0.0.92
0.0.93
Fixed in
0.0.94
References
Updated Jul 01, 2026 · Source: OSV.dev | ||
0.0.73
patch
1 CVE
CVE-2025-62373
PYSEC-2026-458
GHSA-c2jg-5cp7-6wc7
Jun 29, 2026
Pipecat: Remote Code Execution by Pickle Deserialization Through LivekitFrameSerializer
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
Remote Code Execution via Unsafe Deserialization in Pipecat's LivekitFrameSerializer SummaryA critical vulnerability exists in Pipecat's DetailsThe Vulnerable code in src/pipecat/serializers/livekit.py:
Python's In summary, whenever Proof of Concept (PoC)The following proof-of-concept demonstrates how an attacker could exploit this vulnerability. It involves two steps: (1) running a Pipecat WebSocket server using the vulnerable serializer, and (2) sending a malicious pickle from a client. Start a Pipecat WebSocket server with the LivekitFrameSerializer enabled – for example, by binding the server to all network interfaces (0.0.0.0) on port 8765. In a Pipecat application, this might be done by specifying the LiveKit serializer in the WebSocket transport parameters. For illustration, the code snippet below starts a server:
In this setup, the server listens on ws://0.0.0.0:8765 (with a default path of /ws for WebSocket connections). It will use Send a malicious pickle payload from a client – an attacker can now connect to the WebSocket and transmit a crafted pickle object that executes code. For instance, the payload below defines a class RCE whose
ImpactIf an application uses It's important to note that by default Pipecat does not use LivekitFrameSerializer (and in fact the class is deprecated), so only systems that explicitly opt into this serializer are affected. However, because the class exists in the codebase, users might inadvertently use it. Any such usage on a public-facing or even internal network service can be exploited by an attacker with network access to the service. The worst-case scenario is an internet-exposed Pipecat server using this serializer, which would allow remote exploitation by anyone with access to the WebSocket port. MitigationUsers of Pipecat should take the following actions to eliminate or reduce the risk of this vulnerability:
In summary, the best mitigation is to stop using the vulnerable LivekitFrameSerializer altogether. If users require LiveKit functionality, upgrade to the latest Pipecat version and switch to the recommended Affected versions
0.0.41
0.0.42
0.0.43
0.0.44
0.0.45
0.0.46
0.0.47
0.0.48
0.0.49
0.0.50
0.0.51
0.0.52
+ 41 more Show less
0.0.53
0.0.54
0.0.55
0.0.56
0.0.57
0.0.58
0.0.59
0.0.60
0.0.61
0.0.62
0.0.63
0.0.64
0.0.65
0.0.66
0.0.67
0.0.68
0.0.69
0.0.70
0.0.71
0.0.72
0.0.73
0.0.74
0.0.75
0.0.76
0.0.77
0.0.78
0.0.79
0.0.80
0.0.81
0.0.82
0.0.83
0.0.84
0.0.85
0.0.86
0.0.87
0.0.88
0.0.89
0.0.90
0.0.91
0.0.92
0.0.93
Fixed in
0.0.94
References
Updated Jul 01, 2026 · Source: OSV.dev | ||
0.0.72
patch
1 CVE
CVE-2025-62373
PYSEC-2026-458
GHSA-c2jg-5cp7-6wc7
Jun 29, 2026
Pipecat: Remote Code Execution by Pickle Deserialization Through LivekitFrameSerializer
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
Remote Code Execution via Unsafe Deserialization in Pipecat's LivekitFrameSerializer SummaryA critical vulnerability exists in Pipecat's DetailsThe Vulnerable code in src/pipecat/serializers/livekit.py:
Python's In summary, whenever Proof of Concept (PoC)The following proof-of-concept demonstrates how an attacker could exploit this vulnerability. It involves two steps: (1) running a Pipecat WebSocket server using the vulnerable serializer, and (2) sending a malicious pickle from a client. Start a Pipecat WebSocket server with the LivekitFrameSerializer enabled – for example, by binding the server to all network interfaces (0.0.0.0) on port 8765. In a Pipecat application, this might be done by specifying the LiveKit serializer in the WebSocket transport parameters. For illustration, the code snippet below starts a server:
In this setup, the server listens on ws://0.0.0.0:8765 (with a default path of /ws for WebSocket connections). It will use Send a malicious pickle payload from a client – an attacker can now connect to the WebSocket and transmit a crafted pickle object that executes code. For instance, the payload below defines a class RCE whose
ImpactIf an application uses It's important to note that by default Pipecat does not use LivekitFrameSerializer (and in fact the class is deprecated), so only systems that explicitly opt into this serializer are affected. However, because the class exists in the codebase, users might inadvertently use it. Any such usage on a public-facing or even internal network service can be exploited by an attacker with network access to the service. The worst-case scenario is an internet-exposed Pipecat server using this serializer, which would allow remote exploitation by anyone with access to the WebSocket port. MitigationUsers of Pipecat should take the following actions to eliminate or reduce the risk of this vulnerability:
In summary, the best mitigation is to stop using the vulnerable LivekitFrameSerializer altogether. If users require LiveKit functionality, upgrade to the latest Pipecat version and switch to the recommended Affected versions
0.0.41
0.0.42
0.0.43
0.0.44
0.0.45
0.0.46
0.0.47
0.0.48
0.0.49
0.0.50
0.0.51
0.0.52
+ 41 more Show less
0.0.53
0.0.54
0.0.55
0.0.56
0.0.57
0.0.58
0.0.59
0.0.60
0.0.61
0.0.62
0.0.63
0.0.64
0.0.65
0.0.66
0.0.67
0.0.68
0.0.69
0.0.70
0.0.71
0.0.72
0.0.73
0.0.74
0.0.75
0.0.76
0.0.77
0.0.78
0.0.79
0.0.80
0.0.81
0.0.82
0.0.83
0.0.84
0.0.85
0.0.86
0.0.87
0.0.88
0.0.89
0.0.90
0.0.91
0.0.92
0.0.93
Fixed in
0.0.94
References
Updated Jul 01, 2026 · Source: OSV.dev |