Critical 9.8 CVSS RCE Hijacks Pipecat Voice Agents
ID: 270ec6ab-abe5-5cfe-92ad-202dbdd74c50
STIX ID: report--270ec6ab-abe5-5cfe-92ad-202dbdd74c50
Feed Name: securityonline.info
Threat Score
**CVE-2025-62373 — Pipecat LivekitFrameSerializer Unsafe Deserialization (RCE):** A critical CVSS 9.8 vulnerability was disclosed in Pipecat where the deprecated LivekitFrameSerializer calls pickle.loads() on untrusted WebSocket data, enabling remote code execution; maintainers released Pipecat 0.0.94 to deprecate the class and recommend immediate upgrades, removal of the unsafe serializer, use of safe formats (JSON/Protobuf/MessagePack), and network hardening.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
