Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2025-53967

34
FAUCET Score

CVE-2025-53967 is a critical command injection vulnerability affecting Framelink Figma MCP Server versions prior to 0.6.3. An unauthenticated remote attacker can execute arbitrary operating system commands by sending a crafted HTTP POST request containing shell metacharacters to an unsanitized input field, which is then used in a curl command. This vulnerability carries a high CVSS score of 8.0, indicating significant risk, as it allows for complete compromise of the MCP process with high confidentiality and integrity impacts, though it requires network access and has high attack complexity. Currently, there is no public exploit code, active exploitation, or significant community discussion surrounding this CVE.

Impacted Technologies

VendorProductVersion(s)CPE
FramelinkFigma MCP Server
>= 0, < 0.6.3CNA affecteddefault unaffected

CVSS Data

CVSS version used by this source: 3.1

8.0HIGH

CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:N

Attack Vector
ADJACENT_NETWORK
Attack Complexity
HIGH
Privileges Required
NONE
User Interaction
NONE
Scope
CHANGED
Confidentiality Impact
HIGH
Integrity Impact
HIGH
Availability Impact
NONE
Exploitability Score
1.6
Impact Score
5.8
CvssVersion
3.1

Exploit Intelligence

EPSS Score
7.42%
Probability of exploitation in next 30 days
EPSS Percentile
93.8%
Percentile rank of EPSS score among Peer Group
As of 2026-07-27
Model: v2026.06.15
This CVE's current EPSS score of 0.0742 is in the 96th percentile among its peer group of 239 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.2 Bluesky, 0.1 Mastodon, and 0.1 GitHub mentions.

Media Mentions

No media coverage found for this CVE.

The average CVE in this peer group has 0.2 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Patch Available

Vendor Patches (4)

npmpatch availablevia ghsa
Product: figma-developer-mcpFixed in: 0.6.3
amazonvendor investigatingvia llm_extracted
leantimevendor investigatingvia llm_extracted
nutanixvendor investigatingvia llm_extracted

Vendor Advisories (4)

leantimellm-leantime-4cc9b737124b02a5HIGH

Framelink Figma MCP Server Command Injection (CVE-2025-53967)

Mar 12, 2026
amazonllm-amazon-0fee968d6386ce43HIGH

Framelink Figma MCP Server Command Injection (CVE-2025-53967)

Mar 12, 2026
nutanixllm-nutanix-b5aec6a9ee00efa1HIGH

Framelink Figma MCP Server Command Injection (CVE-2025-53967)

Mar 12, 2026
npmGHSA-gxw4-4fc5-9gr5high

figma-developer-mcp vulnerable to command injection in get_figma_data tool

Sep 30, 2025

References

github.com / GLips/Figma-Context-MCP/blob/96b3852669c5eed65e4a6e20406c25504d9196f2/src/utils/fetch-with-retry.ts
github.com / GLips/Figma-Context-MCP/releases/tag/v0.6.3
imperva.com / blog/another-critical-rce-discovered-in-a-popular-mcp-server