Vulnerability library
Security checkNovember 15, 2025

Open WebUI Affected by an External Model Server (Direct Connections) Code Injection via SSE Events

Understand the exposure, see the recommended fix, and check whether your own website has related weaknesses.

High severitynpmopen-webui

Check your website

Find this and other vulnerabilities with a free scan.

Your scan runs on your computer. No account required.

Description

Open WebUI v0.6.33 and below contains a code injection vulnerability in the Direct Connections feature that allows malicious external model servers to execute arbitrary JavaScript in victim browsers via Server-Sent Event (SSE) execute events.

Recommendation

Update the open-webui package to the latest compatible version. Followings are version details:

  • Affected version(s): <= 0.6.34
  • Patched version(s): 0.6.35

References

Could your website be exposed too?

SmartScanner can check your website for Open WebUI Affected by an External Model Server (Direct Connections) Code Injection via SSE Events and gives you actionable findings to investigate.

Start a free scan

Related Issues

See something that needs correcting? Let us knowUpdated November 15, 2025