<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Sat, 03 Oct 2026 07:20:21 +0000</lastBuildDate>
    <item>
      <title>EUVD-2026-260799</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-260799</link>
      <description>EUVD-2026-260799</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-260799</guid>
    </item>
    <item>
      <title>fkie_cve-2025-64496</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2025-64496</link>
      <description>&lt;p&gt;Open WebUI is a self-hosted artificial intelligence platform designed to operate entirely offline. Versions 0.6.224 and prior contain a code injection vulnerability in the Direct Connections feature that allows malicious external model servers to execute arbitrary JavaScript in victim browsers via Server-Sent Event (SSE) execute events. This leads to authentication token theft, complete account takeover, and when chained with the Functions API, enables remote code execution on the backend server. The attack requires the victim to enable Direct Connections (disabled by default) and add the attacker&amp;#39;s malicious model URL, achievable through social engineering of the admin and subsequent users. This issue is fixed in version 0.6.35.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Open WebUI is a self-hosted artificial intelligence platform designed to operate entirely offline. Versions 0.6.224 and prior contain a code injection vulnerability in the Direct Connections feature that allows malicious external model servers to execute arbitrary JavaScript in victim browsers via Server-Sent Event (SSE) execute events. This leads to authentication token theft, complete account takeover, and when chained with the Functions API, enables remote code execution on the backend server. The attack requires the victim to enable Direct Connections (disabled by default) and add the attacker&amp;#39;s malicious model URL, achievable through social engineering of the admin and subsequent users. This issue is fixed in version 0.6.35.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2025-64496</guid>
    </item>
    <item>
      <title>GHSA-cm35-v4vp-5xvx — Open WebUI Affected by an External Model Server (Direct Connections) Code Injection via SSE Events</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-cm35-v4vp-5xvx</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; npm: open-webui, PyPI: open-webui&lt;/p&gt;
&lt;p&gt;### Summary
Open WebUI v0.6.33 and below contains a code injection vulnerability in the Direct Connections feature that allows malicious external model servers to execute arbitrary JavaScript in victim browsers via Server-Sent Event (SSE) `execute` events. This leads to authentication token theft, complete account takeover, and when chained with the Functions API, enables remote code execution on the backend server. The attack requires the victim to enable Direct Connections (disabled by default) and add the attacker&amp;#39;s malicious model URL, achievable through social engineering of the admin and subsequent users.&lt;/p&gt;
&lt;p&gt;### Details
ROOT CAUSE ANALYSIS:&lt;/p&gt;
&lt;p&gt;Open WebUI&amp;#39;s Direct Connections feature allows users to add external OpenAI-compatible 
model servers without proper validation of the Server-Sent Events (SSE) these servers emit.&lt;/p&gt;
&lt;p&gt;VULNERABLE COMPONENT: Frontend SSE Event Handler&lt;/p&gt;
&lt;p&gt;The frontend JavaScript code processes SSE events from external servers and specifically 
handles an `execute` event type that triggers arbitrary JavaScript execution:&lt;/p&gt;
&lt;p&gt;// Approximate vulnerable code location (frontend SSE handler)
if (event.type === &amp;#39;execute&amp;#39;) {
  const func = new Function(event.data.code);  // CRITICAL: Unsafe code execution
  await func();
}&lt;/p&gt;
&lt;p&gt;VULNERABILITY DETAILS:&lt;/p&gt;
&lt;p&gt;1. No validation of external server trustworthiness
2. No allowlist of trusted model providers  
3. No event type whitelisting or filtering
4. Direct execution of code from `execute` events using `new Function()`
5. No sandb…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; npm: open-webui, PyPI: open-webui&lt;/p&gt;
&lt;p&gt;### Summary
Open WebUI v0.6.33 and below contains a code injection vulnerability in the Direct Connections feature that allows malicious external model servers to execute arbitrary JavaScript in victim browsers via Server-Sent Event (SSE) `execute` events. This leads to authentication token theft, complete account takeover, and when chained with the Functions API, enables remote code execution on the backend server. The attack requires the victim to enable Direct Connections (disabled by default) and add the attacker&amp;#39;s malicious model URL, achievable through social engineering of the admin and subsequent users.&lt;/p&gt;
&lt;p&gt;### Details
ROOT CAUSE ANALYSIS:&lt;/p&gt;
&lt;p&gt;Open WebUI&amp;#39;s Direct Connections feature allows users to add external OpenAI-compatible 
model servers without proper validation of the Server-Sent Events (SSE) these servers emit.&lt;/p&gt;
&lt;p&gt;VULNERABLE COMPONENT: Frontend SSE Event Handler&lt;/p&gt;
&lt;p&gt;The frontend JavaScript code processes SSE events from external servers and specifically 
handles an `execute` event type that triggers arbitrary JavaScript execution:&lt;/p&gt;
&lt;p&gt;// Approximate vulnerable code location (frontend SSE handler)
if (event.type === &amp;#39;execute&amp;#39;) {
  const func = new Function(event.data.code);  // CRITICAL: Unsafe code execution
  await func();
}&lt;/p&gt;
&lt;p&gt;VULNERABILITY DETAILS:&lt;/p&gt;
&lt;p&gt;1. No validation of external server trustworthiness
2. No allowlist of trusted model providers  
3. No event type whitelisting or filtering
4. Direct execution of code from `execute` events using `new Function()`
5. No sandb…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-cm35-v4vp-5xvx</guid>
    </item>
    <item>
      <title>PYSEC-2026-1729 — Open WebUI Affected by an External Model Server (Direct Connections) Code Injection via SSE Events</title>
      <link>https://cve.radiocsirt.org/vuln/pysec-2026-1729</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; PyPI: open-webui&lt;/p&gt;
&lt;p&gt;### Summary
Open WebUI v0.6.33 and below contains a code injection vulnerability in the Direct Connections feature that allows malicious external model servers to execute arbitrary JavaScript in victim browsers via Server-Sent Event (SSE) `execute` events. This leads to authentication token theft, complete account takeover, and when chained with the Functions API, enables remote code execution on the backend server. The attack requires the victim to enable Direct Connections (disabled by default) and add the attacker&amp;#39;s malicious model URL, achievable through social engineering of the admin and subsequent users.&lt;/p&gt;
&lt;p&gt;### Details
ROOT CAUSE ANALYSIS:&lt;/p&gt;
&lt;p&gt;Open WebUI&amp;#39;s Direct Connections feature allows users to add external OpenAI-compatible 
model servers without proper validation of the Server-Sent Events (SSE) these servers emit.&lt;/p&gt;
&lt;p&gt;VULNERABLE COMPONENT: Frontend SSE Event Handler&lt;/p&gt;
&lt;p&gt;The frontend JavaScript code processes SSE events from external servers and specifically 
handles an `execute` event type that triggers arbitrary JavaScript execution:&lt;/p&gt;
&lt;p&gt;// Approximate vulnerable code location (frontend SSE handler)
if (event.type === &amp;#39;execute&amp;#39;) {
  const func = new Function(event.data.code);  // CRITICAL: Unsafe code execution
  await func();
}&lt;/p&gt;
&lt;p&gt;VULNERABILITY DETAILS:&lt;/p&gt;
&lt;p&gt;1. No validation of external server trustworthiness
2. No allowlist of trusted model providers  
3. No event type whitelisting or filtering
4. Direct execution of code from `execute` events using `new Function()`
5. No sandb…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; PyPI: open-webui&lt;/p&gt;
&lt;p&gt;### Summary
Open WebUI v0.6.33 and below contains a code injection vulnerability in the Direct Connections feature that allows malicious external model servers to execute arbitrary JavaScript in victim browsers via Server-Sent Event (SSE) `execute` events. This leads to authentication token theft, complete account takeover, and when chained with the Functions API, enables remote code execution on the backend server. The attack requires the victim to enable Direct Connections (disabled by default) and add the attacker&amp;#39;s malicious model URL, achievable through social engineering of the admin and subsequent users.&lt;/p&gt;
&lt;p&gt;### Details
ROOT CAUSE ANALYSIS:&lt;/p&gt;
&lt;p&gt;Open WebUI&amp;#39;s Direct Connections feature allows users to add external OpenAI-compatible 
model servers without proper validation of the Server-Sent Events (SSE) these servers emit.&lt;/p&gt;
&lt;p&gt;VULNERABLE COMPONENT: Frontend SSE Event Handler&lt;/p&gt;
&lt;p&gt;The frontend JavaScript code processes SSE events from external servers and specifically 
handles an `execute` event type that triggers arbitrary JavaScript execution:&lt;/p&gt;
&lt;p&gt;// Approximate vulnerable code location (frontend SSE handler)
if (event.type === &amp;#39;execute&amp;#39;) {
  const func = new Function(event.data.code);  // CRITICAL: Unsafe code execution
  await func();
}&lt;/p&gt;
&lt;p&gt;VULNERABILITY DETAILS:&lt;/p&gt;
&lt;p&gt;1. No validation of external server trustworthiness
2. No allowlist of trusted model providers  
3. No event type whitelisting or filtering
4. Direct execution of code from `execute` events using `new Function()`
5. No sandb…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/pysec-2026-1729</guid>
    </item>
  </channel>
</rss>
