PT-2026-84361 · Lllyasviel · Fooocus

CVE-2026-51974

·

Published

2026-09-01

·

Updated

2026-09-01

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions lllyasviel Fooocus versions 2.1.854 through 2.5.5
Description An eval() injection issue exists in the get list() function within modules/meta parser.py. This allows remote attackers to execute arbitrary Python code by providing a specially crafted styles payload inside the EXIF metadata of an uploaded image file. eval() injection occurs when an application passes untrusted input to the eval() function, which executes the input as code.
Recommendations Update lllyasviel Fooocus to a version later than 2.5.5. As a temporary mitigation, restrict the upload of image files containing EXIF metadata until the software is updated.

Exploit

Fix

Code Injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-51974

Affected Products

Fooocus