HomeSecurityOpen WebUI bug turns 'free model' into backdoor

Bug in Open WebUI turns 'free model' into backdoor

Security researchers have identified a serious flaw in Open WebUI, a self-hosted business interface for large language models, that allows external model servers, connected via the Direct Connections, to inject malicious code and hijack AI workloads. The issue, tracked as CVE-2025-64496, results from insecure handling of server-sent events (SSE), allowing account hijacking and, in some cases with elevated privileges, remote code execution (RCE) on infrastructure servers.

See also: React2Shell vulnerability used to install Linux Backdoors

Open WebUI

According to findings by Cato CTRL, if an employee connects Open WebUI to an attacker-controlled model endpoint, such as under the guise of a 'free alternative to GPT-4', the frontend can be tricked into silently executing imported JavaScript. This code steals JSON Web Tokens (JWTs) from the browser environment, giving attackers persistent access to the victim's AI workspace, documents, conversations, and embedded API keys.

The bug affects Open WebUI versions up to 0.6.34 and is fixed in version 0.6.35, with businesses urged to implement the update without delay.

Cato researchers said the problem is Direct Connections, a feature intended to allow users to connect Open WebUI to external OpenAI-compatible model servers.

The platform's SSE handler trusts incoming events from these servers, especially those marked as '{type: execute}', and executes their content via a dynamic JavaScript constructor. When a user connects to a malicious server, which can be easily activated through social engineering, that server can broadcast an SSE with executable JavaScript.

See also: Exploiting vulnerabilities in Sneeit WordPress and ICTBroadcast fuels Frost botnet

Bug in Open WebUI turns 'free model' into backdoor

This script runs with full access to the browser's storage layer, including the JWT used for authentication. "Open WebUI stores the JWT token in localStorage," Cato researchers said in a blog post. The attack requires the victim to enable Direct Connections (disabled by default) and add the attacker's malicious model URL, according to a description from NVD.

The risk doesn't stop at account takeover. If the compromised account has workspace.tools, attackers can exploit this session token to push authenticated Python code through the Open WebUI Tools API, which runs without sandboxing or validation. This turns a browser-level compromise into full remote code execution on the infrastructure server.

Once an attacker gains access to Python execution, they can install persistence mechanisms, move to internal networks, access sensitive data stores, or perform side-channel attacks. The bug received a high severity rating of 8/10 from NVD and 7.3/10 from GitHub.

The fix in Open WebUI version 0.6.35 includes a complete ban on ' execute ' SSE events from Direct Connections, but any organization still using older versions remains exposed.

See also: MuddyWater targets Turkey-Israel-Azerbaijan with UDPGangster Backdoor

Bug in Open WebUI turns 'free model' into backdoor

Additionally, the researchers recommended moving authentication to short-lived cookies and HttpOnly with rotation. "Combine with strict CSP and prohibit dynamic code evaluation," they added.

Selecting the team

🔒 Protect your privacy with Proton VPN

Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.

  • ✔ No-logs, based in Switzerland (except 14-Eyes)
  • ✔ NetShield: blocks ads, trackers & malicious domains
  • ✔ Covers all devices — free version available
Try Proton VPN for free — 30-day money-back guarantee →

The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Absentee Mia
Absentee Miahttps://www.secnews.gr/politiki-syntaxis/
Member of the Editorial Team of SecNews. He writes about cybersecurity, online fraud, privacy and technology. All articles follow the SecNews Editorial Policy.

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS