logo

High-Severity Flaw in Open WebUI Affects AI Connections

ID: 6a727e2d-b6cc-500f-ab99-1fb33fea667e

STIX ID: report--6a727e2d-b6cc-500f-ab99-1fb33fea667e

Feed Name: Infosecurity Magazine (News)

Threat Score
65/100

Date Published: 2026-01-06

Date Updated: 2026-04-22

...
...

A high-severity (7.3/10) vulnerability, CVE-2025-64496, affects Open WebUI versions 0.6.34 and older when the Direct Connections feature is enabled: a malicious OpenAI-compatible model server can send crafted server-sent events that execute JavaScript in a user's browser to steal JWTs from localStorage, enabling account takeover, data exposure and potential remote code execution for users with elevated workspace.permissions; Open WebUI patched the issue in v0.6.35+.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.