Security Digest: November 7, 2025 - 2 Critical Vulnerabilities
Today's critical security alerts highlight severe vulnerabilities in Open WebUI affecting both frontend and backend operations. Immediate action is required to prevent unauthorized access and potential remote code execution.
· 3 min read
Security Digest: November 7, 2025 - 2 Critical Vulnerabilities
Executive Summary
Today's critical security alerts highlight severe vulnerabilities in Open WebUI affecting both frontend and backend operations. Immediate action is required to prevent unauthorized access and potential remote code execution.
Critical Vulnerabilities
CVE-2025-64495: DOM XSS in Open WebUI Prompt Insertion
- Impact: Attackers can execute arbitrary JavaScript, leading to account compromise or remote code execution on the server.
- Affected Systems: Open WebUI npm and pip packages with 'Insert Prompt as Rich Text' enabled.
- Immediate Action: Disable 'Insert Prompt as Rich Text' in user settings immediately.
- Mitigation: Apply DOMPurify to sanitize HTML before assignment to
.innerHTML.
CVE-2025-64496: Code Injection via Direct Connections in Open WebUI
- Impact: Malicious servers can inject JavaScript, steal authentication tokens, and execute code on the backend.
- Affected Systems: Open WebUI v0.6.33 and below, with Direct Connections enabled.
- Immediate Action: Disable Direct Connections in the admin panel and remove untrusted model servers.
- Mitigation: Implement strict validation and sandboxing for SSE events from external servers.
What to Do Now
- Disable 'Insert Prompt as Rich Text' and Direct Connections immediately in all instances.
- Sanitize all user inputs using recommended libraries like DOMPurify.
- Review and audit external connections and remove any unverified URLs.
- Monitor network traffic for unusual activities and check for unauthorized access attempts.
Related Resources
- Upcoming internal blog post on Open WebUI vulnerabilities (release after patch).
- Official Open WebUI advisories and updates.