By vendor

Pipecat vulnerabilities

Known CVEs affecting Pipecat products, prioritized by severity, with SEC.co remediation and detection guidance.

1 published vulnerability

  • CVE-2026-44716HIGH 7.5

    Pipecat, an open-source Python framework for building voice and conversational AI agents, contains a path traversal vulnerability in its development runner. When started with the --folder flag, the runner exposes an unauthenticated file download endpoint that fails to validate user-supplied filenames. An attacker on the network can craft specially-encoded URLs to read files anywhere on the system that the Pipecat process can access—such as SSH keys, API credentials, configuration files, and system files. The vulnerability affects versions 0.0.90 through 1.1.x and has been fixed in version 1.2.0.