I Stood Up a Vulnerable AI Chatbot and Watched It Fall. CVE-2025-64496, Every Step.
Full attack chain against Open WebUI v0.6.33 -- from a chat message to root RCE, admin JWT forgery, and persistent backdoor. CVE-2025-64496 exploitation with every command and dead end documented.