PT-2025-53840 · Unknown · Framelink Figma Mcp Server

Published

2025-09-30

·

Updated

2026-03-07

·

CVE-2025-15061

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Framelink Figma MCP Server (affected versions not specified)
Description This issue allows remote attackers to execute arbitrary code on affected installations of Framelink Figma MCP Server without authentication. The flaw resides within the fetchWithRetry method due to insufficient validation of user-supplied strings before they are used in system calls. An attacker can exploit this to execute code with the privileges of the service account. The vulnerability is related to command injection.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

RCE

OS Command Injection

Command Injection

Weakness Enumeration

Related Identifiers

CVE-2025-15061
GHSA-GXW4-4FC5-9GR5
ZDI-25-1197

Affected Products

Framelink Figma Mcp Server