Junglewise Threat Intelligence

CVE-2025-53967: figma-developer-mcp command injection in get_figma_data tool

CVE-2025-53967 · Severity: low · CVSS 3.1 · Published 2025-09-30

Vendors: npm.

Executive brief

figma-developer-mcp is a Model Context Protocol server that enables AI tools to access Figma design files. A command injection vulnerability allows attackers to execute arbitrary system commands on the server by injecting malicious input into the get_figma_data tool, potentially compromising systems running the vulnerable server and exposing sensitive data.

Technical details

The vulnerability is a command injection flaw (CWE-77) caused by unsanitized user input being passed directly to child_process.exec() and curl commands in the fetchWithRetry function. The MCP Server constructs shell commands using unvalidated URL and header parameters containing user-controlled data, allowing attackers to inject shell metacharacters (|, >, &&, etc.). An attacker can exploit this by calling the get_figma_data tool with a malicious fileKey parameter like $(id>/tmp/TEST), which executes arbitrary commands under the server's process privileges. The vulnerability requires no authentication or special privileges and can be triggered through direct tool calls or indirect prompt injection. The issue is fixed in version 0.6.3 and above by replacing child_process.exec with child_process.execFile and implementing input validation.

Affected products

  • GLips figma-developer-mcp <= 0.6.2

Timeline

  • 2025-09-30: disclosed: Advisory published

References