CVE-2025-31114 CRITICAL

CVE-2025-31114: Fooocus webui vulnerable to Remote Code Execution

Vendor Lllyasviel
Product Fooocus
Weakness CWE-434 · Unrestricted file upload
Published August 11, 2026
Last update August 11, 2026

CVSS base score

9.3/10
Attack vector Network
Attack complexity Low
Privileges required None
User interaction None
Confidentiality
Integrity

CVSS vector

CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N

What the vulnerability does

01Description

Fooocus is an image generating software. In versions 2.5.5 and prior, the Fooocus web UI is vulnerable to remote code execution due to the unsafe use of eval when processing metadata JSON. An attacker with access to the Fooocus web UI may be able to execute arbitrary code on the instance. As of time of publication, no known patched versions are available, but a suggested fix pull request is available.

Key dates

02Disclosure timeline

August 11, 2026 CVE published

Related vulnerabilities

04Related CVE