{"id":"CVE-2025-53967","title":"Framelink Figma MCP Server before 0.6.3 allows an unauthenticated remote attacker to execute arbitrary operating system commands via a crafted HTTP POST request with shell metacharacters in input that is used by a fetchWithRetry curl com…","summary":"Framelink Figma MCP Server before 0.6.3 allows an unauthenticated remote attacker to execute arbitrary operating system commands via a crafted HTTP POST request with shell metacharacters in input that is used by a fetchWithRetry curl com…","severity":"high","cvss":8,"cvssVector":"CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:N","cwe":["CWE-420"],"published":"2025-10-08","updated":"2026-10-08","sourceUpdated":"2026-10-08T13:10:00.200","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2025-53967","references":[{"url":"https://github.com/GLips/Figma-Context-MCP/blob/96b3852669c5eed65e4a6e20406c25504d9196f2/src/utils/fetch-with-retry.ts#L34","label":"cve@mitre.org"},{"url":"https://github.com/GLips/Figma-Context-MCP/releases/tag/v0.6.3","label":"cve@mitre.org"},{"url":"https://www.imperva.com/blog/another-critical-rce-discovered-in-a-popular-mcp-server/","label":"cve@mitre.org"}],"tags":["nvd"],"epss":0.05829,"epssPercentile":0.9297,"ingestedAt":"2026-10-08T13:42:55.013Z","slug":"CVE-2025-53967","body":"## Overview\n\nFramelink Figma MCP Server before 0.6.3 allows an unauthenticated remote attacker to execute arbitrary operating system commands via a crafted HTTP POST request with shell metacharacters in input that is used by a fetchWithRetry curl command. The vulnerable endpoint fails to properly sanitize user-supplied input, enabling the attacker to inject malicious commands that are executed with the privileges of the MCP process. Exploitation requires network access to the MCP interface.\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.","depth":"twilight","depthScore":45,"depthScoreParts":{"impact":44,"likelihood":1.2,"exploitation":0,"ransomware":0},"changes":[]}