CyberRota Analysis
AI-GeneratedThe eval() injection vulnerability in the get_list function of lllyasviel Fooocus versions 2.1.854 to 2.5.5 allows remote attackers to execute arbitrary Python code by exploiting crafted styles payloads in the EXIF metadata of uploaded image files. This could lead to unauthorized access or manipulation of the system, making it critical for users of affected versions to prioritize patching or mitigating this vulnerability. Organizations utilizing this software should assess their exposure and implement necessary security measures immediately.
Public Exploit Signal
A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.
Note: these links are listed for security research and verification purposes only.
Original NVD Description
An eval() injection vulnerability in the get_list function in modules/meta_parser.py in lllyasviel Fooocus 2.1.854 through 2.5.5 allows remote attackers to execute arbitrary Python code via a crafted styles payload in the EXIF metadata of an uploaded image file.