Critical severityNVD Advisory· Published Aug 11, 2026· Updated Aug 11, 2026
CVE-2025-31114
CVE-2025-31114
Description
Fooocus is an image generating software. In versions 2.5.5 and prior, the Fooocus web UI is vulnerable to remote code execution due to the unsafe use of eval when processing metadata JSON. An attacker with access to the Fooocus web UI may be able to execute arbitrary code on the instance. As of time of publication, no known patched versions are available, but a suggested fix pull request is available.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
2- Range: <=2.5.5
Patches
Vulnerability mechanics
References
3News mentions
0No linked articles in our index yet.