HIGH7.5PyPI
PYSEC-2026-2877· CVE-2026-44716, GHSA-3363-2ph6-35whPipecat: Path Traversal in Pipecat Runner `/files` Endpoint — Arbitrary File Read via `%2F`-Encoded Separator
Modified: 7/13/2026
package
pkg:pypi/pipecat-ai
Pipecat: Path Traversal in Pipecat Runner `/files` Endpoint — Arbitrary File Read via `%2F`-Encoded Separator
Modified: 7/13/2026
Pipecat: Telephony WebSocket `/ws` Unauthenticated Call-Control Abuse via Attacker-Supplied Call SID
Modified: 7/13/2026
Pipecat: Remote Code Execution by Pickle Deserialization Through LivekitFrameSerializer
Modified: 7/1/2026
Pipecat: Path Traversal in Pipecat Runner `/files` Endpoint — Arbitrary File Read via `%2F`-Encoded Separator
Modified: 7/13/2026
Pipecat: Remote Code Execution by Pickle Deserialization Through LivekitFrameSerializer
Modified: 6/29/2026
Pipecat: Telephony WebSocket `/ws` Unauthenticated Call-Control Abuse via Attacker-Supplied Call SID
Modified: 7/13/2026