PatchSiren

pipecat-ai CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

HIGH pipecat-ai CVE published 2026-07-09

CVE-2026-54695

The CVE record for CVE-2026-54695 was published on 2026-07-09T19:17:06.540Z and has not been modified since then. The NVD entry is currently Undergoing Analysis. This vulnerability affects Pipecat framework versions prior to 1.4.0, allowing unauthenticated call-control attacks. The Pipecat development runner registers a /ws WebSocket endpoint for telephony testing that accepts connections without authenti [truncated]

HIGH pipecat-ai CVE published 2026-06-10

CVE-2026-44716

CVE-2026-44716 is a high-severity path traversal vulnerability in Pipecat, a Python framework for building real-time voice and multimodal conversational agents. The vulnerability exists in Pipecat's development runner (src/pipecat/runner/run.py) from version 0.0.90 to before version 1.2.0. When the runner is started with the --folder flag, it exposes a GET /files/{filename:path} download endpoint. The fil [truncated]