CVE-2026-44716 | pipecat-ai pipecat up to 1.1.x HTTP Request run.py path path traversal (GHSA-3363-2ph6-35wh)
A vulnerability described as critical has been identified in pipecat-ai pipecat up to 1.1.x. The affected element is an unknown function of the file src/pipecat/runner/run.py of the component HTTP Request Handler. Such manipulation of the argument path leads to path traversal.
This vulnerability is documented as CVE-2026-44716. The attack can be executed remotely. There is not any exploit available.
Upgrading the affected component is recommended.