CVE-2025-53967High· 8.0▾ TwilightFramelink Figma MCP Server before 0.6.3 allows an unauthenticated remote attacker to execute arbitrary operating system commands via a crafted HTTP POST request with shell metacharacters in input that is used by a fetchWithRetry curl com…
▾ Twilight zone — High severity, or a signal on a lesser flaw
impact 44 · likelihood 1.2 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via NVD
Last analysed / modified upstream
5.8%
Framelink Figma MCP Server before 0.6.3 allows an unauthenticated remote attacker to execute arbitrary operating system commands via a crafted HTTP POST request with shell metacharacters in input that is used by a fetchWithRetry curl command. The vulnerable endpoint fails to properly sanitize user-supplied input, enabling the attacker to inject malicious commands that are executed with the privileges of the MCP process. Exploitation requires network access to the MCP interface.
Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
Connected by shared product, vendor, weakness, or advisory.
CVE-2025-56558Low· 3.0The Dyson MQTT server (2022 and possibly later) allows publications and subscriptions by a client that has the correct values of AWS_ACCESS_KEY_ID, AWS_SECRET_ACCESS_KEY, AWS_SESSION_TOKEN, and device serial number, even if a device (suc…
CVE-2025-62820Medium· 4.9Slack Nebula before 1.9.7 mishandles CIDR in some configurations and thus accepts arbitrary source IP addresses within the Nebula network.
CVE-2026-102134Medium· 5.4Kiteworks Core did not apply its gateway-level API security controls to every request authenticated through the platform's central authentication service
CVE-2023-28840High· 7.5Moby is an open source container framework developed by Docker Inc
CVE-2026-61909Low· 3.5An issue was discovered in Cyrus IMAP before 3.12.4
CVE-2023-28842Medium· 6.8moby: Encrypted overlay network with a single endpoint is unauthenticated (CVE-2023-28842)