Figma is a collaborative design and prototyping platform primarily distributed through desktop clients, with a modestly represented vulnerability footprint centered on OS command injection issues arising from input handling in the application layer. Current severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Figma over time
Signals from CVEs in this vendor scope (1 CVEs).
1 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2025-56803HIGH Figma Desktop for Windows version 125.6.5 contains a command injection vulnerability in the local plugin loader. An attacker can execute arbitrary OS commands by setting a crafted | Sep 3, 2025 | 8.4 | 27 | NO | NO |
Signals from CVEs in this vendor scope (1 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Figma.
Media articles that mention a CVE ID that affects a product developed by Figma — matched by CVE ID, not by vendor name.