{"id":"CVE-2025-53967","aliases":["GHSA-gxw4-4fc5-9gr5"],"url":"https://o3.security/vulnerability/CVE-2025-53967","summary":"figma-developer-mcp vulnerable to command injection in get_figma_data tool","details":"Framelink Figma MCP Server before 0.6.3 allows an unauthenticated remote attacker to execute arbitrary operating system commands via a crafted HTTP POST request with shell metacharacters in input that is used by a fetchWithRetry curl command. The vulnerable endpoint fails to properly sanitize user-supplied input, enabling the attacker to inject malicious commands that are executed with the privileges of the MCP process. Exploitation requires network access to the MCP interface.","published":"2025-10-08T00:00:00Z","modified":"2026-07-15T01:48:54.311689671Z","cvss":{"score":8,"severity":"HIGH","vector":"CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:N"},"epss":null,"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"npm","name":"figma-developer-mcp","fixedVersion":"0.6.3"}],"fix":null,"references":[{"type":"WEB","url":"https://github.com/GLips/Figma-Context-MCP/blob/96b3852669c5eed65e4a6e20406c25504d9196f2/src/utils/fetch-with-retry.ts#L34"},{"type":"WEB","url":"https://github.com/GLips/Figma-Context-MCP/releases/tag/v0.6.3"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2025/53xxx/CVE-2025-53967.json"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2025-53967"},{"type":"ARTICLE","url":"https://www.imperva.com/blog/another-critical-rce-discovered-in-a-popular-mcp-server/"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-07-15T01:48:54.311689671Z"}}