@livekit/protocol is vulnerable to Cryptographic Downgrade
75
High Risk
LiveKit SIP helpers merge trunk, dispatch-rule, and request media settings when building outbound and inbound call parameters. When only the trunk defines SRTP via MediaEncryption, affected versions call Upgrade() before the trunk value is applied, pinning Media.Encryption to disabled and causing generated INVITEs to omit SRTP offers. Calls that rely on trunk-only encryption can therefore negotiate or attempt cleartext RTP even when SRTP was required. The patch treats the protobuf zero encryption value as unset during upgrade so trunk-level MediaEncryption is preserved when request and rule fields are empty.
You are affected if you are using a version that falls within the vulnerable range.
@livekit/protocol is vulnerable to Cryptographic Downgrade in versions 1.45.8 - 1.45.8.
Upgrade the @livekit/protocol library to the patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

SOC 2Compliant
ISO 27001Compliant