Cybersecurity researchers have revealed details of a now-patched vulnerability in the popular figma-developer-mcp Model Context Protocol (MCP) server. The vulnerability could allow attackers to achieve code execution.

The vulnerability, tracked as CVE-2025-53967 (CVSS score: 7.5), is a command injection that results from unsanitized use of user input, opening the way for a scenario where an attacker can send arbitrary system commands.
“The server constructs and executes shell commands using unauthenticated user input directly within command-line strings. This introduces the possibility of shell metacharacter injection (|, >, &&, etc.),” according to a GitHub announcement about the bug. “Successful exploitation could lead to remote code execution.”
See also: PoC exploit published for critical vulnerabilities in Lua engine
Since the Framelink Figma MCP server exposes various tools for performing operations in Figma (using AI-powered coding agents like Cursor), an attacker could trick the MCP client into performing unintended actions via indirect prompt injection.
Cybersecurity firm Imperva, which discovered and reported the issue in July 2025, described CVE -2025-53967 as a “design oversight” in the fallback mechanism that could allow malicious actors to achieve full remote code execution, putting developers at risk of data exposure.
The command injection flaw “occurs during the construction of a command-line instruction used to send traffic to the Figma API endpoint,” said security researcher Yohann Sillam.

The exploitation chain takes place through several steps:
1. The MCP client sends an Initialize request to the MCP endpoint to obtain an mcp-session-id that is used in the next communication with the MCP server.
2. The client sends a JSONRPC request to the MCP server with the tools/call method to call tools such as get_figma_data or download_figma_images.
See also: CISA added Zimbra vulnerability to KEV Catalog
The issue, at its core, lies in “src/utils/fetch-with-retry.ts“, which first attempts to retrieve content using the standard fetch API and, if that fails, proceeds to execute a curl command via child_process.exec — which introduces the command injection bug.
“Because the curl command is constructed by directly interpolating URLs and headers into a shell command string, a malicious actor could create a specially crafted URL or header value that inserts arbitrary shell commands,” Imperva said. “This could lead to remote code execution (RCE) on the host.”
Figma vulnerability: Attack example
In a proof-of-concept attack, a remote malicious actor on the same network (e.g., a public Wi-Fi or a compromised corporate device) can trigger the bug by sending a series of requests to the vulnerable MCP.
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

Alternatively, an attacker could trick a victim into visiting a specially crafted website as part of a DNS rebinding attack. The vulnerability has been addressed in version 0.6.3 of figma-developer-mcp, which was released on September 29, 2025.
See also: Vulnerability in Kibana Crowdstrike Connector exposes protected credentials
Other protective measures include avoiding using child_process.exec with untrusted input and switching to child_process.execFile which eliminates the risk of shell interpretation.
“tools AI development continue to evolve and gain adoption, it is essential that security keeps pace with innovation,” the company said. “This vulnerability is a stark reminder that even tools intended to run locally can become powerful entry points for attackers.”
