CVE-2025-53967 is a critical command injection vulnerability affecting Framelink Figma MCP Server versions prior to 0.6.3. An unauthenticated remote attacker can execute arbitrary operating system commands by sending a crafted HTTP POST request containing shell metacharacters to an unsanitized input field, which is then used in a curl command. This vulnerability carries a high CVSS score of 8.0, indicating significant risk, as it allows for complete compromise of the MCP process with high confidentiality and integrity impacts, though it requires network access and has high attack complexity. Currently, there is no public exploit code, active exploitation, or significant community discussion surrounding this CVE.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
| Framelink | Figma MCP Server | >= 0, < 0.6.3CNA affecteddefault unaffected |
CVSS version used by this source: 3.1
CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:N
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.2 Bluesky, 0.1 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.2 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Framelink Figma MCP Server Command Injection (CVE-2025-53967)
Mar 12, 2026Framelink Figma MCP Server Command Injection (CVE-2025-53967)
Mar 12, 2026Framelink Figma MCP Server Command Injection (CVE-2025-53967)
Mar 12, 2026figma-developer-mcp vulnerable to command injection in get_figma_data tool
Sep 30, 2025