Cato CTRL™ Threat Research: Vulnerability Discovered in Open WebUI Enables Account Takeover and Remote Code Execution (CVE-2025-64496)
ID: b0c41c0b-2735-57f8-ab1e-d2933d6c22c4
STIX ID: report--b0c41c0b-2735-57f8-ab1e-d2933d6c22c4
Feed Name: Cato Networks
**Executive Summary:** Cato CTRL researcher discovered CVE-2025-64496 in Open WebUI (v0.6.34 and older) where the Direct Connections feature accepts streamed SSE "execute" events that are evaluated in the browser (via new Function()), allowing JWT theft and account takeover; if the compromised account has workspace.tools permission, the attacker can create malicious Tools that execute untrusted Python via exec() on the backend, resulting in RCE and full server compromise; the issue is patched in v0.6.35 and newer and mitigations include updating, restricting Direct Connections, enforcing least-privilege for workspace.tools, and improving token handling and CSP.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
