← العودة للجدول
CVE-2026-44716
CVE-2026-44716 — Pipecat is an open-source Python framework for building real-time voice and mult
📅 2026-06-10
🟠 High 🔥 No NVD Exploit Vulnerability CVSS 7.5

📋 الوصف الكامل

Pipecat is an open-source Python framework for building real-time voice and multimodal conversational agents. From version 0.0.90 to before version 1.2.0, a path traversal vulnerability exists in Pipecat's development runner (src/pipecat/runner/run.py). When the runner is started with the --folder flag, it exposes a GET /files/{filename:path} download endpoint. The filename path parameter is

💻 الأنظمة المتأثرة

⚠️ نوع التهديد

Exploit

🔗 CVE ID

CVE-2026-44716

📡 المصدر

NVD

✅ الحلول والتخفيف

Update to v0.0.90

🔗 المصدر الأصلي ← 📘 NVD ← ⚡ CISA KEV ←