
The information displayed in the AIM should not be reported as representing the official views of the OECD or of its member countries.
A high-severity vulnerability (CVE-2025-64496) in Open WebUI, an open-source AI interface, allowed attackers to exploit the Direct Connections feature to execute arbitrary code and take over user accounts. The flaw enabled theft of authentication tokens and, in some cases, remote code execution on backend servers, risking data and system compromise.[AI generated]






























.webp)