Severe Framelink Figma MCP Vulnerability Lets Hackers Execute Code Remotely
A recently disclosed vulnerability in the figma-developer-mcp Model Context Protocol (MCP) server could allow attackers to execute code remotely due to a command injection flaw from unsanitized user input. This vulnerability, tracked as CVE-2025-53967, has a CVSS score of 7.5 and has been patched.