High-severity flaw in Open WebUI may enable remote code execution via Direct Connections
Cato Networks disclosed a high-severity vulnerability in Open WebUI (CVE-2025-64496) that can enable JavaScript execution in the browser, leading to account takeover by stealing authentication tokens. If a compromised user has the workspace.tools permission, attackers could...
Posted On 08 Jan 2026















