logo

Critical 9.8 CVSS RCE Hijacks Pipecat Voice Agents

ID: 270ec6ab-abe5-5cfe-92ad-202dbdd74c50

STIX ID: report--270ec6ab-abe5-5cfe-92ad-202dbdd74c50

Feed Name: securityonline.info

Threat Score
75/100

Date Published: 2026-04-27

Date Updated: 2026-04-27

Author: Ddos

...
...

**CVE-2025-62373 — Pipecat LivekitFrameSerializer Unsafe Deserialization (RCE):** A critical CVSS 9.8 vulnerability was disclosed in Pipecat where the deprecated LivekitFrameSerializer calls pickle.loads() on untrusted WebSocket data, enabling remote code execution; maintainers released Pipecat 0.0.94 to deprecate the class and recommend immediate upgrades, removal of the unsafe serializer, use of safe formats (JSON/Protobuf/MessagePack), and network hardening.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.