Loading
An open source framework for voice (and multimodal) assistants
Declares an LLM dependency since 2024-05-13 (version 0.0.9).
Advisories that name pipecat-ai as affected. Advisory records do not state an ecosystem, so packages with the same name in other ecosystems also match. For a version-exact check of your own dependencies, use Stack Check.
| Advisory | Severity | Affected | Fixed in | Published |
|---|---|---|---|---|
| CVE-2026-54695GHSA-j8cv-x86q-rj85: Pipecat: Telephony WebSocket `/ws` Unauthenticated Call-Control Abuse via Attacker-Supplied Call SID | High | >= 0.0.77, < 1.4.0 | 1.4.0 | 2026-06-18 |
| CVE-2026-44716GHSA-3363-2ph6-35wh: Pipecat: Path Traversal in Pipecat Runner `/files` Endpoint — Arbitrary File Read via `%2F`-Encoded Separator | High | >= 0.0.90, < 1.2.0 | 1.2.0 | 2026-05-15 |
| CVE-2025-62373GHSA-c2jg-5cp7-6wc7: Pipecat: Remote Code Execution by Pickle Deserialization Through LivekitFrameSerializer | Critical | >= 0.0.41, < 0.0.94 | 0.0.94 | 2026-04-23 |
As declared in PyPI metadata for version 1.12.0. Optional extras are listed with their extra name.
Among the packages in the registry; not every dependent on PyPI.