CVE-2025-64496CWE-501CWE-829CWE-830CWE-95

Open WebUI Affected by an External Model Server (Direct Connections) Code Injection via SSE Events

High · published November 8, 2025

CVSS v3.1
7.3
EPSS
8%
Percentile
94.2
In the wild
Unconfirmed
What it is

⚡ A cunning code injection vulnerability hides in the Direct Connections feature of Open WebUI, allowing attackers to execute arbitrary JavaScript in victim browsers. 🔥 Think of it like a sneaky waiter who brings a dish to your table that’s laced with an ingredient you didn’t order — if a malicious external model server is added, it gets the chance to spice things up in your browser without any checks! This is no picnic! An attacker could easily steal authentication tokens and take full control of user accounts. If they chain this with the Functions API, they could even execute remote code on the backend server, putting your entire system at risk!

Put simply

Think of it like a sneaky waiter who brings a dish to your table that’s laced with an ingredient you didn’t order — if a malicious external model server is added, it gets the chance to spice things up in your browser without any checks! The vulnerability in versions 0.6.224 and prior allows malicious model URLs to execute JavaScript in browsers via Server-Sent Events (SSE), which can lead to account takeovers and backend control.

What to do

This is no picnic! An attacker could easily steal authentication tokens and take full control of user accounts. If they chain this with the Functions API, they could even execute remote code on the backend server, putting your entire system at risk! Update to version 0.6.35 immediately to patch this vulnerability. Ensure that Direct Connections are disabled unless absolutely necessary, and educate users about the risks of social engineering tactics. You've got this! Stay vigilant and follow these steps to keep your platform safe! 🛡️

The record
Technical detail
CVSS v3.1
7.3 · HIGH
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:N
CVSS v4.0
Not supplied
EPSS
0.07770 · 94.2th percentile
Weaknesses
CWE-501 · Trust Boundary Violation; CWE-829 · Inclusion of Functionality from Untrusted Control Sphere; CWE-830 · Inclusion of Web Functionality from an Untrusted Source; CWE-95 · Improper Neutralization of Directives in Dynamically Evaluated Code ('Eval Injection')
Published
2025-11-08T01:29Z
EPSS history
Timeline
  • 08 NOV 01:29Z
    Open WebUI Affected by an External Model Server (Direct Connections) Code Injection via SSE Events
    cvelistv5