agent-postmortems a structured database of real AI-agent failures

← all incidents

hazard high confidence: confirmed status: final

Command-injection RCE in the Framelink Figma MCP server, triggerable via indirect prompt injection

2025-framelink-figma-mcp-rce · 2025-09-29

The widely used Framelink Figma MCP server (figma-developer-mcp) built shell commands from unsanitized input in its curl fallback path (CVE-2025-53967), allowing remote code execution. An agent using the tool could be induced via indirect prompt injection to trigger it. Reported by Imperva and fixed in version 0.6.3.

System

Framework
MCP (Model Context Protocol) client with Framelink Figma MCP server
Tools
figma-developer-mcp, figma
Vendor
Framelink
Autonomy
supervised-autonomous

Classification

Primary class
prompt-injection
Chain
prompt-injection/indirect → unsafe-action
Attack vector
untrusted-content
Causation
entity: human · intentionality: intentional · timing: pre-deployment

Trigger

The server's fallback curl mechanism (the fetchWithRetry path) interpolated unsanitized URL and header values directly into a shell command string. An attacker-controlled input reaching the get_figma_data tool could inject arbitrary system commands; an agent could be steered to send that input via indirect prompt injection, executing commands on the host even over STDIO transport.

Root cause

Unvalidated user input was concatenated into a shell command (OS command injection), and the MCP tool was reachable by an agent that treats retrieved content as actionable. The combination turned a design-data tool into a remote-code-execution path.

Contributing factors

  • Shell commands were constructed from unsanitized URL/header input.
  • The tool could be invoked by an agent acting on untrusted retrieved content.
  • The package was widely adopted (600,000+ downloads), widening exposure.

Detection

Discovered and reported to the maintainers by Imperva on 2025-07-08; assigned CVE-2025-53967 and covered by security outlets on public disclosure.

Recovery

The maintainers released a complete fix in version 0.6.3 on 2025-09-29; users on earlier versions were advised to upgrade.

Prevention

Never build shell commands from unsanitized input (use argument arrays / avoid shell interpolation); validate and sanitize tool inputs; sandbox MCP servers; treat agent-reachable tool inputs as untrusted; keep MCP dependencies patched.

Blast radius

Data
Exploitation could allow arbitrary command execution on the host, enabling manipulation of design files, exfiltration of intellectual property, or lateral movement into broader networks. confidential
User harm
A disclosed vulnerability with a released fix; no in-the-wild exploitation was reported. none-reported
Scope
users of figma-developer-mcp < 0.6.3 (600,000+ downloads)
Reversibility
reversible

References

CWE
CWE-78
OWASP LLM
LLM01 LLM06
MITRE ATLAS
AML.T0051
Tags
mcp figma rce command-injection cve

Sources

Cite this incident

@misc{2025-framelink-figma-mcp-rce,
  title = {Command-injection RCE in the Framelink Figma MCP server, triggerable via indirect prompt injection},
  year = {2025},
  howpublished = {agent-postmortems},
  url = {https://swarmproof.github.io/agent-postmortems/2025-framelink-figma-mcp-rce/}
}