Open WebUI Affected by an External Model Server (Direct Connections) Code Injection via SSE Events
- Severity:
- High
Description
Open WebUI v0.6.33 and below contains a code injection vulnerability in the Direct Connections feature that allows malicious external model servers to execute arbitrary JavaScript in victim browsers via Server-Sent Event (SSE) execute events.
Recommendation
Update the open-webui package to the latest compatible version. Followings are version details:
- Affected version(s): <= 0.6.34
- Patched version(s): 0.6.35
References
- GHSA-cm35-v4vp-5xvx
- CVE-2025-64496
- CWE-501
- CWE-829
- CWE-830
- CWE-95
- CAPEC-310
- OWASP 2021-A3
- OWASP 2021-A4
- OWASP 2021-A6
- OWASP 2021-A8
Related Issues
- open-webui Vulnerable to Stored XSS via Model Description - CVE-2026-44721
- Open WebUI vulnerable to Stored DOM XSS via prompts when 'Insert Prompt as Rich Text' is enabled resulting in ATO/RCE - CVE-2025-64495
- Open WebUI Vulnerable to Stored DOM XSS via Note 'Download PDF - CVE-2025-65959
- Lightning Flow Scanner Vulnerable to Code Injection via Unsafe Use of `new Function()` in APIVersion Rule - CVE-2025-67750
You might also like:
- Tags:
- npm
- open-webui
Anything's wrong? Let us know Last updated on November 15, 2025


