CVE-2025-64496: high-severity vulnerability in open-webui
Open WebUI Affected by an External Model Server (Direct Connections) Code Injection via SSE Events
Published · Updated
21Vexday Risk Score
No sign of exploitation. No public exploitation artifact known so far.
ssvc Trackcvss 7.3epss 7.8%
exploitation probability
7.8%top 6% of all CVEs
observed exploitation
nono source reports it
Open WebUI is a self-hosted artificial intelligence platform designed to operate entirely offline. Versions 0.6.224 and prior contain a code injection vulnerability in the Direct Connections feature that allows malicious external model servers to execute arbitrary JavaScript in victim browsers via Server-Sent Event (SSE) execute events. This leads to authentication token theft, complete account takeover, and when chained with the Functions API, enables remote code execution on the backend server. The attack requires the victim to enable Direct Connections (disabled by default) and add the attacker's malicious model URL, achievable through social engineering of the admin and subsequent users. This issue is fixed in version 0.6.35.
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:N
Affected products
open-webui · open-webuiRelated CVEs — open-webui
In the same product, most dangerous first.
CVE-2025-65958HIGHOpen WebUI vulnerable to Server-Side Request Forgery (SSRF) via Arbitrary URL Processing in /api/v1/retrieval/process/webEPSS 4.4%CVE-2026-44551CRITICALOpen WebUI: LDAP Empty Password Authentication BypassEPSS 1.6%CVE-2026-45397MEDIUMOpen WebUI: Unauthenticated RAG Configuration DisclosureEPSS 0.8%CVE-2026-45395HIGHOpen WebUI: Missing `workspace.tools` Authorization Check on Tool Update Endpoint Allows Privilege Escalation to Code ExecutionEPSS 0.7%CVE-2026-87011HIGHOpen WebUI: Unauthenticated requests can stall the server via uncached OIDC fetches in back-channel logoutEPSS 0.6%CVE-2026-56398HIGHOpen WebUI - Stored Cross-Site Scripting via OAuth Picture Claim SVG Data URIEPSS 0.6%