pipecat-ai vulnerabilities
CVEs whose affected-version data names the pipecat-ai package (pip). Each record lists the affected and patched versions; check a specific version with the dependency checker or POST /api/sbom.
2 CVEsRSS
CVE-2026-54695High· 7.5Pipecat: Telephony WebSocket `/ws` Unauthenticated Call-Control Abuse via Attacker-Supplied Call SID
Pipecat: Telephony WebSocket `/ws` Unauthenticated Call-Control Abuse via Attacker-Supplied Call SID
▾ Twilightpipecat-ai · pipecat-aiEPSS 0.56%via GHSA
CVE-2026-44716High· 7.5Pipecat: Path Traversal in Pipecat Runner `/files` Endpoint — Arbitrary File Read via `%2F`-Encoded Separator
Pipecat: Path Traversal in Pipecat Runner `/files` Endpoint — Arbitrary File Read via `%2F`-Encoded Separator
▾ Twilightpipecat-ai · pipecat-aiEPSS 0.42%via OSV