logo

Framelink Figma MCP Server Opens Orgs to Agentic AI Compromise

ID: b718d4b9-2230-5d3f-bc0a-360ff350b2b9

STIX ID: report--b718d4b9-2230-5d3f-bc0a-360ff350b2b9

Feed Name: Dark Reading

Threat Score
70/100

Date Published: 2025-10-08

Date Updated: 2026-05-05

Author: Tara Seals

...
...

Researchers disclosed a high-severity command-injection vulnerability in Framelink's Figma MCP server (figma-developer-mcp) that uses unsanitized user input with child_process.exec, enabling remote code execution (CVE-2025-53967, CVSS 7.5). The report warns that thousands of MCP servers are deployed with weak or missing authentication, increasing the risk of large-scale compromise, and recommends upgrading to version 0.6.3+, auditing vulnerable systems, and monitoring logs for suspicious command activity.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.