๐Ÿ” CVE Alert

CVE-2025-31114

UNKNOWN 0.0

Fooocus webui vulnerable to Remote Code Execution

CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th

Fooocus is an image generating software. In versions 2.5.5 and prior, the Fooocus web UI is vulnerable to remote code execution due to the unsafe use of eval when processing metadata JSON. An attacker with access to the Fooocus web UI may be able to execute arbitrary code on the instance. As of time of publication, no known patched versions are available, but a suggested fix pull request is available.

CWE CWE-95
Vendor lllyasviel
Product fooocus
Published Aug 11, 2026
Last Updated Aug 11, 2026
Stay Ahead of the Next One

Get instant alerts for lllyasviel fooocus

Be the first to know when new unknown vulnerabilities affecting lllyasviel fooocus are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

Affected Versions

lllyasviel / Fooocus
<= 2.5.5

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
securitylab.github.com: https://securitylab.github.com/advisories/GHSL-2024-196_Fooocus/ github.com: https://github.com/lllyasviel/Fooocus/issues/3552 github.com: https://github.com/lllyasviel/Fooocus/pull/4207