CVE-2025-62373Patch(pipecat / pipecat)

LOWCVSS 9.8 · CRITICAL

Exploit discussion active in current signal (1 latest mentions)

Immediate actions

  • Patch pipecat pipecat systems immediately
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft

Recommended action window: High priority (within 72h)

NVD description

Pipecat is an open-source Python framework for building real-time voice and multimodal conversational agents. Versions 0.0.41 through 0.0.93 have a vulnerability in `LivekitFrameSerializer` – an optional, non-default, undocumented frame serializer class (now deprecated) intended for LiveKit integration. The class's `deserialize()` method uses Python's `pickle.loads()` on data received from WebSocket clients without any validation or sanitization. This means that a malicious WebSocket client can send a crafted pickle payload to execute arbitrary code on the Pipecat server. The vulnerable code resides in `src/pipecat/serializers/livekit.py` (around line 73), where untrusted WebSocket message data is passed directly into `pickle.loads()` for deserialization. If a Pipecat server is configured to use LivekitFrameSerializer and is listening on an external interface (e.g. 0.0.0.0), an attacker on the network (or the internet, if the service is exposed) could achieve remote code execution (RCE) on the server by sending a malicious pickle payload. Version 0.0.94 contains a fix. Users of Pipecat should avoid or replace unsafe deserialization and improve network security configuration. The best mitigation is to stop using the vulnerable LivekitFrameSerializer altogether. Those who require LiveKit functionality should upgrade to the latest Pipecat version and switch to the recommended `LiveKitTransport` or another secure method provided by the framework. Additionally, always follow secure coding practices: never trust client-supplied data, and avoid Python pickle (or similar unsafe deserialization) in network-facing components.

2.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-502

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • pipecat

Threat summary

  • Public PoC is present in monitored signal
  • Patch or workaround signal is available
  • 6 mentions across 4 observed days
  • Momentum state: stable

What's happening

  • PoC mentioned or linked in 1 signal
  • Patch or workaround mentioned in 3 signals
  • Technical details provided in 5 signals
  • Disclosure: 2 classified signals
  • General: 1 classified signal
  • Peaked 2d ago at 2 mentions (2026-04-27); latest day: 1
  • 6 total mentions across 4 days

Affected systems

Vendors
Products
pipecat

Deep dive

Activity timeline6 mentions / 4d
01122Mentions · 2026-04-24: 1Mentions · 2026-04-27: 2Mentions · 2026-04-28: 2Mentions · 2026-05-01: 1PoC Mentioned / Linked · 2026-04-27: 1Patch / Workaround · 2026-04-27: 2Patch / Workaround · 2026-04-28: 1Technical Details · 2026-04-24: 1Technical Details · 2026-04-27: 2Technical Details · 2026-04-28: 204-2404-2704-2805-01
Signal classification3 categories
Patch
350.0%
Disclosure
233.3%
General
116.7%
Referenced assets4 URLs
Classification over time
DateTotalLabels
2026-04-241
Disclosure1
2026-04-272
Patch2
2026-04-282
Disclosure1Patch1
2026-05-011
General1
Full discourse6 posts
  • Gray Hats@the_yellow_fall
    Patch

    Critical 9.8 CVSS RCE in Pipecat (CVE-2025-62373)! Unsafe pickle deserialization allows remote code execution. Patch to v0.0.94 immediately to secure agents. #Pipecat #RCE #CyberSecurity #Python #InfoSec #CVE202562373 #VoiceAI #AIPhishing https://securityonline.info/pipecat-rce-vulnerability-cve-2025-62373-pickle-deserialization/ https://t.co/vuydRrI7hz

    Post summary

    Critical CVE‑2025‑62373 in Pipecat allows RCE via unsafe pickle deserialization. Immediate patch to v0.0.94 is recommended.

    0401541.8K
    12.5K followersView on X
  • Upwind Security MDR@UpwindMDR
    Patch

    🚨 Critical - Pipecat RCE via Unsafe Deserialization (CVE-2025-62373) A malicious WebSocket client can send a crafted pickle payload to pickle.loads() in LivekitFrameSerializer.deserialize() - no validation, no sanitization → full remote code execution on the server. 👉 Upgrade to 0.0.94 immediately

    Post summary

    The post highlights a critical RCE in LivekitFrameSerializer via unsafe deserialization and urges immediate upgrade to v0.0.94 to mitigate the vulnerability.

    00040855
    237 followersView on X
  • Misbar | مسبار@MisbarSec
    Patch

    📌 ثغرة تنفيذ عن بعد حرجة في إطار العمل Pipecat لتعزيز وكلاء الصوت تم الكشف عن ثغرة أمنية حرجة في إطار العمل Pipecat، وهو إطار عمل مفتوح المصدر شائع الاستخدام في بناء وكلاء الصوت والوكلاء التخاطبيين. تم تعيين الثغرة كـ CVE-2025-62373 وتحمل درجة خطورة 9.8 على مقياس CVSS. تسمح هذه الثغرة للمهاجمين بتنفيذ تعليمات عن بعد، مما قد يؤدي إلى اختراق الوكلاء الصوتيين. يُنصح بتحديث الإطار العمل إلى أحدث إصدار وتطبيق التصحيحات الأمنية اللازمة. 🔗 للمزيد: https://securityonline.info/pipecat-rce-vulnerability-cve-2025-62373-pickle-deserialization/

    Post summary

    The notice highlights a critical remote command execution vulnerability in the Pipecat framework (CVE-2025-62373), urging users to update to the latest version and apply recommended patches.

    00030766
    267 followersView on X
  • IntegSec@integ_sec
    General

    CVE-2025-62373: Pipecat Deserialization Flaw - What It Means for Your Business and How to Respond https://hubs.li/Q04f7Fc40

    Post summary

    The provided excerpt is merely a headline about CVE‑2025‑62373, offering no concrete evidence of PoC, exploit, active usage, patching, detailed vulnerability data, or debunking.

    00000930
    29 followersView on X
  • cvereports@_cvereports
    Disclosure

    CVE-2025-62373: CVE-2025-62373: Remote Code Execution via Insecure Deserialization in Pipecat LivekitFrameSerializer CVE-2025-62373 is a critical remote code execution (RCE) vulnerability in Pipecat, an open-source Python framework for building real-t... https://cvereports.com/reports/CVE-2025-62373

    Post summary

    The post announces CVE-2025-62373 as a critical RCE vulnerability in Pipecat caused by insecure deserialization, offering only surface details without any PoC, exploit code, active use, or patch information.

    00000637
    36 followersView on X
  • PulsePatch.io@pulsepatchio
    Disclosure

    `Pipecat` is vulnerable to remote code execution (CVE-2025-62373) via insecure Pickle deserialization in `LivekitFrameSerializer`. This allows for arbitrary code execution. #Pipecat #RCE #InfoSec https://www.pulsepatch.io/posts/cve-2025-62373-pipecat-rce-pickle-deserialization

    Post summary

    The post announces a newly disclosed CVE-2025-62373 in Pipecat that enables remote code execution via insecure pickle deserialization, but no PoC, exploit code, patch, or evidence of active exploitation is provided.

    00000506
    12 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Apppipecatpipecat---

Explore more