Open WebUI carried CVE-2025-64496, a high-severity code injection flaw in Direct Connection featuresExploitation might allow account takeover and RCE through malicious mannequin URLs and Capabilities API chainingPatch v0.6.35 provides middleware protections; customers urged to limit Direct Connections and monitor device permissions
Support Greater and Subscribe to view content
This is premium stuff. Subscribe to read the entire article.











