CVE-2025-64496 is a high-severity code injection vulnerability in Open WebUI versions 0.6.224 and prior, specifically within its Direct Connections feature. An attacker can exploit this by tricking users into enabling Direct Connections and adding a malicious model URL, leading to arbitrary JavaScript execution in victim browsers. This allows for authentication token theft, complete account takeover, and potential remote code execution on the backend server when chained with the Functions API. While not actively exploited or having public exploit code, the vulnerability has garnered significant community discussion and media coverage, indicating awareness of its potential impact.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 0.6.35CPE matchmatch criteria | cpe:2.3:a:openwebui:open_webui:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.3 Bluesky, 0.1 Mastodon, and 0.1 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Open WebUI Remote Code Execution (CVE-2025-64496)
Jan 19, 2026Open WebUI Remote Code Execution (CVE-2025-64496)
Jan 19, 2026Open WebUI Remote Code Execution (CVE-2025-64496)
Jan 19, 2026Open WebUI Remote Code Execution (CVE-2025-64496)
Jan 19, 2026Open WebUI Remote Code Execution (CVE-2025-64496)
Jan 19, 2026Open WebUI Affected by an External Model Server (Direct Connections) Code Injection via SSE Events
Nov 7, 2025