Advisory Database
  • Advisories
  • Dependency Scanning
  1. pypi
  2. ›
  3. pipecat-ai
  4. ›
  5. CVE-2026-54695

CVE-2026-54695: Pipecat: Telephony WebSocket `/ws` Unauthenticated Call-Control Abuse via Attacker-Supplied Call SID

June 18, 2026

The pipecat development runner registers a /ws WebSocket endpoint for telephony testing that accepts connections without any authentication. An unauthenticated remote attacker who can reach an exposed runner endpoint can connect to this endpoint, send a crafted Twilio handshake message containing an attacker-supplied callSid, and cause the server to issue an authenticated Twilio REST API hang-up request against that call SID using the server operator’s own credentials. This may allow the attacker to forcibly terminate an active call on the victim’s Twilio account if the attacker knows or obtains a valid call SID for that account. Equivalent unauthenticated call-control sinks exist for Telnyx and Plivo. Maintainers are evaluating the final CVSS 3.1 score.

References

  • github.com/advisories/GHSA-j8cv-x86q-rj85
  • github.com/pipecat-ai/pipecat/pull/4660
  • github.com/pipecat-ai/pipecat/security/advisories/GHSA-j8cv-x86q-rj85
  • nvd.nist.gov/vuln/detail/CVE-2026-54695

Code Behaviors & Features

Detect and mitigate CVE-2026-54695 with GitLab Dependency Scanning

Secure your software supply chain by verifying that all open source dependencies used in your projects contain no disclosed vulnerabilities. Learn more about Dependency Scanning →

Affected versions

All versions starting from 0.0.77 before 1.4.0

Fixed versions

  • 1.4.0

Solution

Upgrade to version 1.4.0 or above.

Impact 7.5 HIGH

CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:N/I:L/A:H

Learn more about CVSS

Weakness

  • CWE-862: Missing Authorization

Source file

pypi/pipecat-ai/CVE-2026-54695.yml

Spotted a mistake? Edit the file on GitLab.

  • Site Repo
  • About GitLab
  • Terms
  • Privacy Statement
  • Contact

Page generated Tue, 23 Jun 2026 12:23:21 +0000.