Description
Open WebUI v0.6.33 and below contains a code injection vulnerability in the Direct Connections feature that allows malicious external model servers to execute arbitrary JavaScript in victim browsers via Server-Sent Event (SSE) execute events.
Recommendation
Update the open-webui package to the latest compatible version. Followings are version details:
- Affected version(s): <= 0.6.34
- Patched version(s): 0.6.35
References
Could your website be exposed too?
SmartScanner can check your website for Open WebUI Affected by an External Model Server (Direct Connections) Code Injection via SSE Events and gives you actionable findings to investigate.
Start a free scanRelated Issues
- open-webui Vulnerable to Stored XSS via Model Description - CVE-2026-44721
- Open WebUI vulnerable to Stored DOM XSS via prompts when 'Insert Prompt as Rich Text' is enabled resulting in ATO/RCE - CVE-2025-64495
- Open WebUI Vulnerable to Stored DOM XSS via Note 'Download PDF - CVE-2025-65959
- Lightning Flow Scanner Vulnerable to Code Injection via Unsafe Use of `new Function()` in APIVersion Rule - CVE-2025-67750


