Vulnerabilities/

Open WebUI Affected by an External Model Server (Direct Connections) Code Injection via SSE Events

Severity:
High

Description

Open WebUI v0.6.33 and below contains a code injection vulnerability in the Direct Connections feature that allows malicious external model servers to execute arbitrary JavaScript in victim browsers via Server-Sent Event (SSE) execute events.

Recommendation

Update the open-webui package to the latest compatible version. Followings are version details:

References

Related Issues

Tags:
npm
open-webui
Anything's wrong? Let us know Last updated on November 15, 2025