PatchSiren

PatchSiren cyber security CVE debrief

CVE-2025-62373 pipecat-ai CVE debrief

CVE-2025-62373 is a critical vulnerability in Pipecat, an open-source Python framework for building real-time voice and multimodal conversational agents. The vulnerability affects versions 0.0.41 through 0.0.93 and allows for remote code execution (RCE) via an optional, non-default, undocumented frame serializer class. The class's `deserialize()` method uses Python's `pickle.loads()` on untrusted WebSocket client data without validation or sanitization, enabling a malicious client to execute arbitrary code on the server. The vulnerability is addressed in version 0.0.94, and users are advised to upgrade and avoid using the vulnerable LivekitFrameSerializer.

Vendor
pipecat-ai
Product
pipecat
CVSS
CRITICAL 9.8
CISA KEV
Not listed in stored evidence
Original CVE published
2026-04-23
Original CVE updated
2026-10-05
Advisory published
2026-04-23
Advisory updated
2026-10-05

Who should care

Defenders and administrators of Pipecat servers, particularly those using versions 0.0.41 through 0.0.93, should assess their exposure and take immediate action to upgrade to version 0.0.94 or later and review their network security configurations.

Why it matters

CVE-2025-62373 is a critical vulnerability in Pipecat that allows for remote code execution via insecure deserialization. Defenders and administrators of Pipecat servers should assess their exposure and take immediate action to upgrade and review their network security configurations.

  • Remote code execution (RCE) on the Pipecat server
  • Potential for arbitrary code execution via crafted pickle payloads
  • Need for immediate upgrade to version 0.0.94 or later
  • Importance of reviewing and improving network security configurations

Technical summary

The vulnerability resides in the `LivekitFrameSerializer` class, specifically in the `deserialize()` method, which uses Python's `pickle.loads()` on untrusted WebSocket client data without validation or sanitization. This allows a malicious client to send a crafted pickle payload to execute arbitrary code on the Pipecat server. The affected product context includes Pipecat versions 0.0.41 through 0.0.93, and defenders should prioritize upgrading to version 0.0.94 or later. The technical impact is critical, with a CVSS score of 9.8, and defenders should review their network security configurations to prevent exposure to untrusted WebSocket clients.

Defensive priority

High priority for upgrading to version 0.0.94 and replacing or avoiding the use of LivekitFrameSerializer. Network security configurations should be reviewed to prevent exposure to untrusted WebSocket clients.

Recommended defensive actions

  • Upgrade to Pipecat version 0.0.94 or later
  • Avoid or replace the use of LivekitFrameSerializer
  • Review and improve network security configurations to prevent exposure to untrusted WebSocket clients
  • Follow secure coding practices to prevent similar vulnerabilities
  • Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up
  • Review compensating controls for exposed systems while remediation is scheduled and verified
  • Track exceptions, retest remediated assets, and close the item only after evidence is documented

Evidence notes

The vulnerability is confirmed in Pipecat versions 0.0.41 through 0.0.93. The fix is available in version 0.0.94. The CVE record and NVD entry provide details on the vulnerability and its impact. Defenders should verify the affected scope, review network security configurations, and assess their exposure to untrusted WebSocket clients. Evidence limits suggest that the vulnerability allows for remote code execution via crafted pickle payloads, and defenders should be cautious of potential arbitrary code execution.

Sources and references

Verified primary and authoritative sources

  • CVE-2025-62373 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2025-62373

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2025-62373 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2025-62373

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

  • Source reference

    Unverified legacy reference

    URL: https://github.com/pipecat-ai/pipecat/security/advisories/GHSA-c2jg-5cp7-6wc7

    [email protected] - Exploit, Mitigation, Vendor Advisory

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.