Eval Injection in Open WebUI - CVE-2025-64496
Published: April 24, 2026
Open WebUI
Detailed vulnerability description
The vulnerability allows a remote user to execute arbitrary JavaScript in the victim's browser.
The vulnerability exists due to improper neutralization of directives in dynamically evaluated code in the frontend SSE event handler when processing Server-Sent Events from an external model server through Direct Connections. A remote user can send a specially crafted SSE execute event to execute arbitrary JavaScript in the victim's browser.
User interaction is required, and exploitation requires Direct Connections to be enabled and the victim to add the attacker's external model URL.