MCPA-2025-0011
highrce-vectors
figma-developer-mcp (Framelink Figma MCP) command injection in get_figma_data (CVE-2025-53967)
figma-developer-mcp before 0.6.3 passes unsanitized input (e.g. the `fileKey` argument) into a shell `curl` invocation inside its fetchWithRetry fallback, allowing an attacker to inject arbitrary operating system commands via shell metacharacters. Exploitable by a crafted request with network access to the MCP interface, or indirectly via prompt injection.
Affected packages
| Ecosystem | Package | Affected versions |
|---|---|---|
| npm | figma-developer-mcp | >= 0, < 0.6.3 |
Identifiers
CVE-2025-53967GHSA-gxw4-4fc5-9gr5CWE-78
References
- advisory https://github.com/advisories/GHSA-gxw4-4fc5-9gr5
- advisory https://nvd.nist.gov/vuln/detail/CVE-2025-53967
- report https://www.imperva.com/blog/another-critical-rce-discovered-in-a-popular-mcp-server/
- fix https://github.com/GLips/Figma-Context-MCP/releases/tag/v0.6.3
Timeline
- Published: 2025-09-29