VYPR
High severity7.5NVD Advisory· Published Jul 9, 2026· Updated Jul 13, 2026

CVE-2026-54695

CVE-2026-54695

Description

Pipecat is an open-source Python framework for building real-time voice and multimodal conversational agents. Prior to 1.4.0, the pipecat development runner registers a /ws WebSocket endpoint for telephony testing that accepts connections without authentication, reads an attacker-supplied callSid from a Twilio stream-start handshake in src/pipecat/runner/utils.py, and passes it to TwilioFrameSerializer so the server can issue an authenticated Twilio REST API hang-up request with the server operator's credentials; equivalent unauthenticated call-control sinks exist for Telnyx and Plivo. This issue is fixed in version 1.4.0.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected packages

Versions sourced from the GitHub Security Advisory.

PackageAffected versionsPatched versions
pipecat-aiPyPI
>= 0.0.77, < 1.4.01.4.0

Affected products

2
  • Pipecat AI/Pipecatllm-fuzzy2 versions
    <1.4.0+ 1 more
    • (no CPE)range: <1.4.0
    • cpe:2.3:a:pipecat:pipecat:*:*:*:*:*:python:*:*range: <1.4.0

Patches

Vulnerability mechanics

References

6

News mentions

0

No linked articles in our index yet.