BTC $71,807
2026 Bull Run Is Building Start trading with 5% OFF all fees
Sign Up Now
BTC $71,807
Bull Run 2026 | 5% Off Fees Open your Binance account today
Sign Up

Critical Figma MCP Vulnerability Allows Remote Code Execution Exploit

Command Injection Vulnerability in figma-developer-mcp MCP Server Allows Remote Code Execution, Fixed in Version 0.6.3

  • A command injection vulnerability was found in the figma-developer-mcp Model Context Protocol (MCP) server.
  • The flaw could allow attackers to run arbitrary system commands and achieve remote code execution.
  • The issue stems from unvalidated user input used in shell commands executed via child_process.exec.
  • The vulnerability was fixed in version 0.6.3 of figma-developer-mcp, released on September 29, 2025.
  • Security experts highlight the risk this flaw poses to AI-powered development tools integrated with Figma and similar platforms.

Cybersecurity researchers disclosed a vulnerability in the figma-developer-mcp Model Context Protocol (MCP) server that could enable attackers to execute arbitrary system commands remotely. The issue was publicly reported on October 8, 2025, and affects the widely used MCP server connected to Figma, an online design platform.

- Advertisement -

The vulnerability, identified as CVE-2025-53967 with a CVSS score of 7.5, results from unsafe handling of user input when constructing shell commands. The server uses unvalidated input directly in command-line strings, allowing shell metacharacter injection such as |, >, &&, enabling attackers to inject and execute malicious commands. This flaw was addressed by Imperva, the cybersecurity company that discovered and reported it in July 2025.

According to the GitHub advisory, exploitation occurs when the MCP client sends requests that invoke tools like get_figma_data or download_figma_images via JSONRPC calls. The root cause lies in the file “src/utils/fetch-with-retry.ts,” which tries to fetch data using the standard API and, if it fails, runs a curl command through child_process.exec. Because inputs are directly embedded in the shell command without validation, attackers can craft inputs that inject arbitrary shell code.

“Because the curl command is constructed by directly interpolating URL and header values into a shell command string, a malicious actor could craft a specially designed URL or header value that injects arbitrary shell commands,” Imperva explained. This leads to remote code execution on the host machine with the server’s privileges.

Attackers on the same network or those who trick users into visiting malicious websites via DNS rebinding attacks can trigger the exploit. The vulnerability was patched in version 0.6.3 of figma-developer-mcp, released on September 29, 2025. The fix includes avoiding the use of child_process.exec with untrusted data and switching to safer methods like child_process.execFile that do not allow shell interpretation.

- Advertisement -

Experts warn that as AI-driven development tools, such as Cursor, increasingly integrate with platforms like Figma, security risks become more critical. The flaw underlines potential dangers when local tools serve as entry points for attackers.

In related news, security researchers at FireTail disclosed that Google’s Gemini AI chatbot has an unresolved ASCII smuggling technique vulnerability. This attack method can bypass security filters and induce harmful behavior, representing a broader challenge for AI systems embedded deeply into enterprise platforms.

✅ Follow BITNEWSBOT on Telegram, Facebook, LinkedIn, X.com, and Google News for instant updates.

Previous Articles:

- Advertisement -
Ad
Altseason Is Loading. Don't watch from the sidelines.
SOL $90.51
DOGE $0.0963
LINK $9.02
SUI $1.00
5% off fees when you sign up
Start Trading
Ad
Pay Less on Every Trade. For Life.
$10K/mo volume Save $60/yr
$50K/mo volume Save $300/yr
$100K/mo volume Save $600/yr
5% off all trading fees when you sign up
Claim Your Discount

Latest News

Cisco Firewall Flaw Actively Exploited in the Wild

Cisco has confirmed active exploitation of a high-severity vulnerability (CVE-2026-20349) in its Secure Firewall...

3 Signs Bitcoin Could Reclaim $100k Sooner – New Study Shows

Bitcoin last traded above $100k in November 2025 before entering a bearish phase.Analysts expect...

AMD Eyes Billions from Helios as AI Revenue Set to Surge in 2027

AMD expects its Helios rack-scale platform to generate billions of dollars in its first...

CFTC orders Kalshi to keep operating amid New York gambling lawsuit

The CFTC invoked emergency authority to order prediction market Kalshi to continue operating, countering...

SEC, CFTC sue Goliath Ventures over $400M crypto Ponzi scheme

The SEC and CFTC filed separate civil lawsuits against Goliath Ventures and founder Christopher...

Must Read

What is Moon Tropica (CAH) – Technology, Tokenomics, Game Preview

Gaming enthusiasts and crypto enthusiasts, hHave you heard about Moon Tropica? If you're longing for that nostalgic feel of classic games from your childhood...
Ad
Altseason Is Loading. These 4 coins are trending right now.
SOL $92.12
DOGE $0.0950
LINK $9.02
SUI $1.02
5% off spot fees when you sign up
Start Trading