Confidence
Medium. Based on ~40 public sources; exact cloud pricing figures and several review quotes were truncated in the snapshots reviewed.
Pricing
Free
Open Source
ModelUsage-based
Monthly feesNot disclosed
HardwareNot disclosed
Free tierYes
Pipecat CloudUsage-based
Pipecat EnterpriseCustom
Sources & method
Analyzed 9/26/2026 - 13 sources - Active CVE history in 2025-26 (RCE, path traversal, missing authorization), patched upstream; HIPAA option on Pipecat Cloud.
official x4review x4security x4news x1
- CVE-2025-62373 / GHSA-c2jg-5cp7-6wc7 — RCE via pickle deserialization, Untrusted pickle deserialization could allow remote code execution; fixed in later releases (April 2026 advisory).
- CVE-2026-44716 — directory traversal, High-severity path traversal in pipecat-ai, disclosed May 2026.
- CVE-2026-54695 — missing authorization (CWE-862), High-severity missing-authorization flaw in versions prior to the patch, July 2026.
- GHSA-j8cv-x86q-rj85 — unauthenticated telephony WebSocket, Call-control /ws endpoint lacked authentication before the June 2026 fix.
Comments
One queue. No nested comments. Give a display name first. Limit: 200 words per comment and 7 comments per day. You can edit or delete yours.
No comments yet.