Remote Code Execution Vulnerability in Fooocus Image Generation Software
CVE-2025-31114
9.3CRITICAL
What is CVE-2025-31114?
Fooocus, an image generating software, contains a vulnerability that allows for remote code execution through the unsafe evaluation of metadata JSON via the web UI. This issue is present in versions 2.5.5 and earlier, whereby an attacker gaining access to the Fooocus web interface could potentially execute arbitrary code on the affected system. While no patched versions are currently available, a proposed fix has been submitted for consideration.
Affected Version(s)
Fooocus <= 2.5.5
