Command-injection RCE in the Framelink Figma MCP server, triggerable via indirect prompt injection
2025-framelink-figma-mcp-rce · 2025-09-29
The widely used Framelink Figma MCP server (figma-developer-mcp) built shell commands from unsanitized input in its curl fallback path (CVE-2025-53967), allowing remote code execution. An agent using the tool could be induced via indirect prompt injection to trigger it. Reported by Imperva and fixed in version 0.6.3.
System
- Framework
- MCP (Model Context Protocol) client with Framelink Figma MCP server
- Tools
- figma-developer-mcp, figma
- Vendor
- Framelink
- Autonomy
- supervised-autonomous
Classification
- Primary class
- prompt-injection
- Chain
- prompt-injection/indirect → unsafe-action
- Attack vector
- untrusted-content
- Causation
- entity: human · intentionality: intentional · timing: pre-deployment
Trigger
The server's fallback curl mechanism (the fetchWithRetry path) interpolated unsanitized URL and header values directly into a shell command string. An attacker-controlled input reaching the get_figma_data tool could inject arbitrary system commands; an agent could be steered to send that input via indirect prompt injection, executing commands on the host even over STDIO transport.
Root cause
Unvalidated user input was concatenated into a shell command (OS command injection), and the MCP tool was reachable by an agent that treats retrieved content as actionable. The combination turned a design-data tool into a remote-code-execution path.
Contributing factors
- Shell commands were constructed from unsanitized URL/header input.
- The tool could be invoked by an agent acting on untrusted retrieved content.
- The package was widely adopted (600,000+ downloads), widening exposure.
Detection
Discovered and reported to the maintainers by Imperva on 2025-07-08; assigned CVE-2025-53967 and covered by security outlets on public disclosure.
Recovery
The maintainers released a complete fix in version 0.6.3 on 2025-09-29; users on earlier versions were advised to upgrade.
Prevention
Never build shell commands from unsanitized input (use argument arrays / avoid shell interpolation); validate and sanitize tool inputs; sandbox MCP servers; treat agent-reachable tool inputs as untrusted; keep MCP dependencies patched.
Blast radius
- Data
- Exploitation could allow arbitrary command execution on the host, enabling manipulation of design files, exfiltration of intellectual property, or lateral movement into broader networks. confidential
- User harm
- A disclosed vulnerability with a released fix; no in-the-wild exploitation was reported. none-reported
- Scope
- users of figma-developer-mcp < 0.6.3 (600,000+ downloads)
- Reversibility
- reversible
References
- CWE
- CWE-78
- OWASP LLM
- LLM01 LLM06
- MITRE ATLAS
- AML.T0051
- Tags
- mcp figma rce command-injection cve
Sources
Cite this incident
Permalink: https://swarmproof.github.io/agent-postmortems/2025-framelink-figma-mcp-rce/
@misc{2025-framelink-figma-mcp-rce,
title = {Command-injection RCE in the Framelink Figma MCP server, triggerable via indirect prompt injection},
year = {2025},
howpublished = {agent-postmortems},
url = {https://swarmproof.github.io/agent-postmortems/2025-framelink-figma-mcp-rce/}
}