Remote Code Execution Vulnerability in Fooocus Image Generation Software
CVE-2025-31114

9.3CRITICAL

Key Information:

Vendor

Lllyasviel

Status
Vendor
CVE Published:
11 August 2026

What is CVE-2025-31114?

Fooocus, an image generating software, contains a vulnerability that allows for remote code execution through the unsafe evaluation of metadata JSON via the web UI. This issue is present in versions 2.5.5 and earlier, whereby an attacker gaining access to the Fooocus web interface could potentially execute arbitrary code on the affected system. While no patched versions are currently available, a proposed fix has been submitted for consideration.

Affected Version(s)

Fooocus <= 2.5.5

References

CVSS V4

Score:
9.3
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.