A critical remote code execution (RCE) vulnerability, tracked as CVE-2025-53967, was discovered and disclosed in the Framelink Figma Model Context Protocol (MCP) server, a widely used open-source project that connects AI coding agents to Figma design data. The flaw, which has since been patched, stemmed from unsanitized user input being used directly in shell command construction, leading to a command injection risk. Attackers could exploit this vulnerability by sending specially crafted requests that inject shell metacharacters, allowing them to execute arbitrary system commands under the privileges of the MCP server process. The vulnerability was identified as a design oversight in the fallback mechanism of the server, specifically in the 'src/utils/fetch-with-retry.ts' file, where the server would attempt to fetch content using the standard API and, upon failure, fall back to executing a shell command with unvalidated input. This opened the door for remote attackers to gain full control over the server, potentially exposing sensitive developer data, design assets, and even compromising connected networks. The Framelink Figma MCP server, launched in February 2025, had quickly become one of the most popular tools in its category, with over 10,000 GitHub stars and 600,000 downloads, making the impact of this vulnerability particularly significant. The server is integral to workflows that leverage AI-powered coding agents like Cursor, which automate and streamline the translation of Figma design data into code. The exploitation process involves the MCP client initiating a session and then sending JSONRPC requests to invoke various tools, such as retrieving Figma data or downloading images, with the vulnerability lying in how these requests were handled. Security researchers from Imperva discovered and reported the issue in July 2025, emphasizing the broader risks associated with rapid AI tooling adoption outpacing secure coding practices. The vulnerability highlighted the need for strict dependency management, regular security reviews, and close monitoring of advisories for projects relying on community-driven AI tools. The GitHub advisory for the flaw detailed the technical aspects of the command injection, warning that successful exploitation could lead to data exposure and further compromise. The incident serves as a cautionary tale for developers and organizations integrating AI-driven automation into their workflows, underscoring the importance of robust input validation and secure design principles. The patch for CVE-2025-53967 was released promptly after disclosure, and users were urged to update their MCP server installations immediately. The case also illustrates the growing trend of attackers targeting the AI development ecosystem, where the intersection of automation and design data presents lucrative opportunities for exploitation. Organizations using the Framelink Figma MCP server were advised to review their security posture and implement recommended mitigations to prevent similar incidents in the future. The vulnerability's discovery and responsible disclosure by Imperva contributed to raising awareness about the security challenges inherent in modern AI and design integration platforms.

Track how attackers are adapting to this technology.
4 events from the most recent confirmed update back to the earliest known activity.
CVE-2025-53967 was publicly listed as a high-severity remote command injection vulnerability affecting Framelink Figma MCP Server versions before 0.6.3. The entry described exploitation via crafted HTTP POST requests containing shell metacharacters and recommended upgrading to 0.6.3 or later.
Imperva published research detailing the critical remote code execution issue in the popular Figma MCP server, describing how unsafe shell command construction could be abused. The disclosure highlighted risks from direct network exposure and DNS rebinding scenarios.
The vulnerability was fixed in Figma MCP server version 0.6.3, released on September 29, 2025. The patched release addressed the command injection issue affecting versions prior to 0.6.3.
Imperva reported a critical command injection flaw in the figma-developer-mcp / Framelink Figma MCP server in July 2025. The issue involved unsanitized user input being passed to shell commands, enabling potential remote code execution.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
Follow how adversaries are adapting to this technology, and where it touches your stack today.
5 references tracked. Mallory keeps watching after this page renders.
scworld.com
Open sourcecvefeed.io
Open sourcethehackernews.com
Open sourcedarkreading.com
Open sourceimperva.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.