Security researchers have identified a serious flaw in Open WebUI, a self-hosted business interface for large language models, that allows external model servers, connected via the Direct Connections, to inject malicious code and hijack AI workloads. The issue, tracked as CVE-2025-64496, results from insecure handling of server-sent events (SSE), allowing account hijacking and, in some cases with elevated privileges, remote code execution (RCE) on infrastructure servers.
See also: React2Shell vulnerability used to install Linux Backdoors

According to findings by Cato CTRL, if an employee connects Open WebUI to an attacker-controlled model endpoint, such as under the guise of a 'free alternative to GPT-4', the frontend can be tricked into silently executing imported JavaScript. This code steals JSON Web Tokens (JWTs) from the browser environment, giving attackers persistent access to the victim's AI workspace, documents, conversations, and embedded API keys.
The bug affects Open WebUI versions up to 0.6.34 and is fixed in version 0.6.35, with businesses urged to implement the update without delay.
Cato researchers said the problem is Direct Connections, a feature intended to allow users to connect Open WebUI to external OpenAI-compatible model servers.
The platform's SSE handler trusts incoming events from these servers, especially those marked as '{type: execute}', and executes their content via a dynamic JavaScript constructor. When a user connects to a malicious server, which can be easily activated through social engineering, that server can broadcast an SSE with executable JavaScript.
See also: Exploiting vulnerabilities in Sneeit WordPress and ICTBroadcast fuels Frost botnet

This script runs with full access to the browser's storage layer, including the JWT used for authentication. "Open WebUI stores the JWT token in localStorage," Cato researchers said in a blog post. The attack requires the victim to enable Direct Connections (disabled by default) and add the attacker's malicious model URL, according to a description from NVD.
The risk doesn't stop at account takeover. If the compromised account has workspace.tools, attackers can exploit this session token to push authenticated Python code through the Open WebUI Tools API, which runs without sandboxing or validation. This turns a browser-level compromise into full remote code execution on the infrastructure server.
Once an attacker gains access to Python execution, they can install persistence mechanisms, move to internal networks, access sensitive data stores, or perform side-channel attacks. The bug received a high severity rating of 8/10 from NVD and 7.3/10 from GitHub.
The fix in Open WebUI version 0.6.35 includes a complete ban on ' execute ' SSE events from Direct Connections, but any organization still using older versions remains exposed.
See also: MuddyWater targets Turkey-Israel-Azerbaijan with UDPGangster Backdoor

Additionally, the researchers recommended moving authentication to short-lived cookies and HttpOnly with rotation. "Combine with strict CSP and prohibit dynamic code evaluation," they added.
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
