© 2025-2026 PySpect
First version without a known vulnerability: 0.0.9
Pipecat: Telephony WebSocket `/ws` Unauthenticated Call-Control Abuse via Attacker-Supplied Call SID
Fixed in: 1.4.0
Pipecat: Path Traversal in Pipecat Runner `/files` Endpoint — Arbitrary File Read via `%2F`-Encoded Separator
Fixed in: 1.2.0
Pipecat: Remote Code Execution by Pickle Deserialization Through LivekitFrameSerializer
Fixed in: 0.0.94