This WebUI vulnerability allows remote code execution – here’s how to stay safe
Open WebUI carried CVE-2025-64496, a high severity code injection vulnerability in Direct Connection functions Exploitation could enable account takeover and RCE via malicious model URLs and Functions API chains Patch v0.6.35 adds middleware protection; users are encouraged to limit direct connections and monitor tool permissions Open WebUI, an open source, self-hosted web interface for interacting […]
This WebUI vulnerability allows remote code execution – here’s how to stay safe Read More »









