PT-2025-53840 · Unknown · Framelink Figma Mcp Server
Published
2025-09-30
·
Updated
2026-03-07
·
CVE-2025-15061
CVSS v3.1
9.8
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Framelink Figma MCP Server (affected versions not specified)
Description
This issue allows remote attackers to execute arbitrary code on affected installations of Framelink Figma MCP Server without authentication. The flaw resides within the
fetchWithRetry method due to insufficient validation of user-supplied strings before they are used in system calls. An attacker can exploit this to execute code with the privileges of the service account. The vulnerability is related to command injection.Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
RCE
OS Command Injection
Command Injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Framelink Figma Mcp Server