CVE-2025-53967
HIGHFramelink Figma MCP Server <0.6.3 - fetchWithRetry Command Injection
Title source: manualDescription
Framelink Figma MCP Server before 0.6.3 allows an unauthenticated remote attacker to execute arbitrary operating system commands via a crafted HTTP POST request with shell metacharacters in input that is used by a fetchWithRetry curl command. The vulnerable endpoint fails to properly sanitize user-supplied input, enabling the attacker to inject malicious commands that are executed with the privileges of the MCP process. Exploitation requires network access to the MCP interface.
References (3)
Core 3
Scores
CVSS v3
8.0
EPSS
0.0001
EPSS Percentile
1.6%
Attack Vector
ADJACENT_NETWORK
CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:N
CISA SSVC
Vulnrichment
Exploitation
poc
Automatable
no
Technical Impact
partial
Details
CWE
CWE-420
Status
published
Products (2)
Framelink/Figma MCP Server
< 0.6.3
npm/figma-developer-mcp
0 - 0.6.3npm
Published
Oct 08, 2025
Tracked Since
Feb 18, 2026