PatchSiren cyber security CVE debrief
CVE-2025-62373 pipecat-ai CVE debrief
CVE-2025-62373 is a critical vulnerability in Pipecat, an open-source Python framework for building real-time voice and multimodal conversational agents. The vulnerability affects versions 0.0.41 through 0.0.93 and allows for remote code execution (RCE) via an optional, non-default, undocumented frame serializer class. The class's `deserialize()` method uses Python's `pickle.loads()` on untrusted WebSocket client data without validation or sanitization, enabling a malicious client to execute arbitrary code on the server. The vulnerability is addressed in version 0.0.94, and users are advised to upgrade and avoid using the vulnerable LivekitFrameSerializer.
- Vendor
- pipecat-ai
- Product
- pipecat
- CVSS
- CRITICAL 9.8
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-04-23
- Original CVE updated
- 2026-10-05
- Advisory published
- 2026-04-23
- Advisory updated
- 2026-10-05
Who should care
Defenders and administrators of Pipecat servers, particularly those using versions 0.0.41 through 0.0.93, should assess their exposure and take immediate action to upgrade to version 0.0.94 or later and review their network security configurations.
Why it matters
CVE-2025-62373 is a critical vulnerability in Pipecat that allows for remote code execution via insecure deserialization. Defenders and administrators of Pipecat servers should assess their exposure and take immediate action to upgrade and review their network security configurations.
- Remote code execution (RCE) on the Pipecat server
- Potential for arbitrary code execution via crafted pickle payloads
- Need for immediate upgrade to version 0.0.94 or later
- Importance of reviewing and improving network security configurations
Technical summary
The vulnerability resides in the `LivekitFrameSerializer` class, specifically in the `deserialize()` method, which uses Python's `pickle.loads()` on untrusted WebSocket client data without validation or sanitization. This allows a malicious client to send a crafted pickle payload to execute arbitrary code on the Pipecat server. The affected product context includes Pipecat versions 0.0.41 through 0.0.93, and defenders should prioritize upgrading to version 0.0.94 or later. The technical impact is critical, with a CVSS score of 9.8, and defenders should review their network security configurations to prevent exposure to untrusted WebSocket clients.
Defensive priority
High priority for upgrading to version 0.0.94 and replacing or avoiding the use of LivekitFrameSerializer. Network security configurations should be reviewed to prevent exposure to untrusted WebSocket clients.
Recommended defensive actions
- Upgrade to Pipecat version 0.0.94 or later
- Avoid or replace the use of LivekitFrameSerializer
- Review and improve network security configurations to prevent exposure to untrusted WebSocket clients
- Follow secure coding practices to prevent similar vulnerabilities
- Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up
- Review compensating controls for exposed systems while remediation is scheduled and verified
- Track exceptions, retest remediated assets, and close the item only after evidence is documented
Evidence notes
The vulnerability is confirmed in Pipecat versions 0.0.41 through 0.0.93. The fix is available in version 0.0.94. The CVE record and NVD entry provide details on the vulnerability and its impact. Defenders should verify the affected scope, review network security configurations, and assess their exposure to untrusted WebSocket clients. Evidence limits suggest that the vulnerability allows for remote code execution via crafted pickle payloads, and defenders should be cautious of potential arbitrary code execution.
Sources and references
Verified primary and authoritative sources
-
CVE-2025-62373 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2025-62373
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2025-62373 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2025-62373
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Source reference
Unverified legacy reference
URL: https://github.com/pipecat-ai/pipecat/security/advisories/GHSA-c2jg-5cp7-6wc7
[email protected] - Exploit, Mitigation, Vendor Advisory
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.