Do these 3 things before closing this tab:
1Clear out junk files and repair common Windows errors2Scan for outdated or missing drivers - takes under a minute3Repair Windows errors before they cause bigger problemsOpen WebUI’s CVE-2025-64496 is a trust-boundary flaw: a hostile model server added through Direct Connections could send an event that runs JavaScript in the user’s browser and steals the user’s authentication token. The reported attack requires Direct Connections to be enabled and an attacker-controlled endpoint to be configured; the feature is disabled by default. The report identifies version 0.6.35 as fixed.
What the Open WebUI vulnerability does
CSO Online reported on January 6, 2026, that CVE-2025-64496 affects how Open WebUI handles server-sent events (SSE) from external model servers configured through Direct Connections. A malicious server can send an SSE event tagged {type: execute}. According to the report, Open WebUI’s frontend processes the event payload through a dynamic JavaScript constructor, allowing the supplied script to run in the browser.
Because the script runs in the application page, it can access browser storage. Cato researchers said Open WebUI stores its JSON Web Token (JWT) in localStorage, where page scripts can read it. A stolen JWT could let an attacker act as the user and potentially access that user’s workspace, documents, chats, and embedded API keys. The report describes this as a route to account takeover.
When the attack is possible
This is not a claim that free models, or model servers generally, are malicious. “Free model” is an example of how an attacker might pitch an endpoint. The risk arises when an application trusts content from an attacker-controlled model server and executes it in the browser.
#1 Best Overall
- Direct Connections must be enabled; CSO reports that the feature is disabled by default.
- The victim must configure a malicious model endpoint through that feature.
- The endpoint must send the crafted execute event while the user is interacting with Open WebUI.
Organizations should treat every externally hosted model endpoint as an untrusted input source, even when it is presented as a convenient or free alternative.
Why backend code execution is conditional
The browser token theft is the initial reported impact. CSO describes a possible further escalation: an attacker who obtains a session token may submit Python code through the Tools API if the compromised account has workspace.tools permissions. The report characterizes that code path as lacking sandboxing or validation.
That escalation is not automatic for every user or deployment. It depends on token theft, the account’s permissions, and the reported Tools API path. Do not equate the browser-side vulnerability alone with guaranteed server-level execution.
Affected versions and the reported fix
CSO identifies Open WebUI versions through 0.6.34 as affected and version 0.6.35 as fixed. The reported fix blocks execute SSE events from Direct Connections. The article does not establish whether later releases have additional changes, so administrators should verify their deployed version and configuration against Open WebUI’s current official release information before deciding that an installation is protected.
What’s actually slowing this PC down?
Pick the symptom - the matching free tool is one click away.
- Check the version of each Open WebUI deployment and compare it with the reported fixed version, 0.6.35.
- Update affected deployments to a fixed release, following the official release guidance for the specific installation.
- Review whether Direct Connections is enabled and inspect every configured endpoint. Disable the feature or remove endpoints that are not trusted or needed.
- Review which accounts have
workspace.toolspermissions and limit those permissions to users who require them. - If a deployment may have processed a hostile endpoint, investigate for possible token exposure and follow your organization’s session-revocation and incident-response procedures.
Severity scores and what they mean
CSO reports two different base scores: 8/10 from the National Vulnerability Database (NVD) and 7.3/10 from GitHub. These figures are attributed secondhand to CSO’s January 2026 report and have not been independently verified here. CSO characterizes them as high; the difference is a reason to retain each score’s source rather than present one as a universal rating.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Additional defenses beyond updating
Cato researchers, as quoted by CSO, recommended short-lived HttpOnly authentication cookies with rotation, a strict content security policy, and banning dynamic code evaluation. These are defense-in-depth measures for developers and operators; they do not replace installing the fix or controlling configured endpoints.
Quick Recap
Best Value
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

