Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Open WebUI’s CVE-2025-64496 is a trust-boundary flaw: a hostile model server added through Direct Connections could send an event that runs JavaScript in the user’s browser and steals the user’s authentication token. The reported attack requires Direct Connections to be enabled and an attacker-controlled endpoint to be configured; the feature is disabled by default. The report identifies version 0.6.35 as fixed.

What the Open WebUI vulnerability does

CSO Online reported on January 6, 2026, that CVE-2025-64496 affects how Open WebUI handles server-sent events (SSE) from external model servers configured through Direct Connections. A malicious server can send an SSE event tagged {type: execute}. According to the report, Open WebUI’s frontend processes the event payload through a dynamic JavaScript constructor, allowing the supplied script to run in the browser.

Because the script runs in the application page, it can access browser storage. Cato researchers said Open WebUI stores its JSON Web Token (JWT) in localStorage, where page scripts can read it. A stolen JWT could let an attacker act as the user and potentially access that user’s workspace, documents, chats, and embedded API keys. The report describes this as a route to account takeover.

When the attack is possible

This is not a claim that free models, or model servers generally, are malicious. “Free model” is an example of how an attacker might pitch an endpoint. The risk arises when an application trusts content from an attacker-controlled model server and executes it in the browser.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
#1 Best Overall
  • Direct Connections must be enabled; CSO reports that the feature is disabled by default.
  • The victim must configure a malicious model endpoint through that feature.
  • The endpoint must send the crafted execute event while the user is interacting with Open WebUI.

Organizations should treat every externally hosted model endpoint as an untrusted input source, even when it is presented as a convenient or free alternative.

Why backend code execution is conditional

The browser token theft is the initial reported impact. CSO describes a possible further escalation: an attacker who obtains a session token may submit Python code through the Tools API if the compromised account has workspace.tools permissions. The report characterizes that code path as lacking sandboxing or validation.

That escalation is not automatic for every user or deployment. It depends on token theft, the account’s permissions, and the reported Tools API path. Do not equate the browser-side vulnerability alone with guaranteed server-level execution.

Affected versions and the reported fix

CSO identifies Open WebUI versions through 0.6.34 as affected and version 0.6.35 as fixed. The reported fix blocks execute SSE events from Direct Connections. The article does not establish whether later releases have additional changes, so administrators should verify their deployed version and configuration against Open WebUI’s current official release information before deciding that an installation is protected.

What’s actually slowing this PC down?

Pick the symptom - the matching free tool is one click away.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
  1. Check the version of each Open WebUI deployment and compare it with the reported fixed version, 0.6.35.
  2. Update affected deployments to a fixed release, following the official release guidance for the specific installation.
  3. Review whether Direct Connections is enabled and inspect every configured endpoint. Disable the feature or remove endpoints that are not trusted or needed.
  4. Review which accounts have workspace.tools permissions and limit those permissions to users who require them.
  5. If a deployment may have processed a hostile endpoint, investigate for possible token exposure and follow your organization’s session-revocation and incident-response procedures.

Severity scores and what they mean

CSO reports two different base scores: 8/10 from the National Vulnerability Database (NVD) and 7.3/10 from GitHub. These figures are attributed secondhand to CSO’s January 2026 report and have not been independently verified here. CSO characterizes them as high; the difference is a reason to retain each score’s source rather than present one as a universal rating.

Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

Additional defenses beyond updating

Cato researchers, as quoted by CSO, recommended short-lived HttpOnly authentication cookies with rotation, a strict content security policy, and banning dynamic code evaluation. These are defense-in-depth measures for developers and operators; they do not replace installing the fix or controlling configured endpoints.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.