CVE-2025-31114

Source
https://cve.org/CVERecord?id=CVE-2025-31114
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2025-31114.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2025-31114
Published
2026-08-11T15:37:33.789Z
Modified
2026-08-18T03:31:04.981390995Z
Severity
  • 9.3 (Critical) CVSS_V4 - CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N CVSS Calculator
Summary
Fooocus webui vulnerable to Remote Code Execution
Details

Fooocus is an image generating software. In versions 2.5.5 and prior, the Fooocus web UI is vulnerable to remote code execution due to the unsafe use of eval when processing metadata JSON. An attacker with access to the Fooocus web UI may be able to execute arbitrary code on the instance. As of time of publication, no known patched versions are available, but a suggested fix pull request is available.

Database specific
{
    "cna_assigner": "GitHub_M",
    "cwe_ids": [
        "CWE-95"
    ],
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2025/31xxx/CVE-2025-31114.json"
}
References

Affected packages

Git / github.com/lllyasviel/fooocus

Affected ranges

Type
GIT
Repo
https://github.com/lllyasviel/fooocus
Events
Introduced
0 Unknown introduced commit / All previous commits are affected
Last affected
Database specific
Show details
{
    "extracted_events": [
        {
            "introduced": "0"
        },
        {
            "last_affected": "2.5.5"
        }
    ],
    "source": "AFFECTED_FIELD"
}

Affected versions

1.*
1.0.35
2.*
2.1.864
2.1.865
2.2.0
2.2.1
2.3.0
2.3.1
Other
release
v2.*
v2.4.0
v2.4.1
v2.4.2
v2.4.3
v2.5.0
v2.5.1
v2.5.2
v2.5.3
v2.5.5

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2025-31114.json"