Check Point — Framelink Figma MCP Server Command Injection (CVE-2025-53967)

AI relevance: This vulnerability directly impacts AI agent ecosystems using Figma MCP servers, allowing attackers to compromise agent tooling infrastructure and potentially gain control over AI workflows that integrate with design systems.

Key Details

  • CVE: CVE-2025-53967
  • Severity: High
  • Affected: Framelink Figma MCP Server prior to 0.6.3
  • Vendor: Check Point Security Advisory CPAI-2025-12898
  • Published: March 12, 2026

Vulnerability Description

A command injection vulnerability in Framelink Figma MCP Server allows unauthenticated remote attackers to execute arbitrary operating system commands via crafted HTTP POST requests containing shell metacharacters in input parameters that are passed to a fetchWithRetry curl command.

Why This Matters

  • MCP (Model Context Protocol) servers are critical infrastructure for AI agent tooling
  • Figma integration is commonly used in AI-assisted design workflows
  • Successful exploitation gives attackers full system-level access
  • No authentication required - network access alone enables exploitation
  • Impacts organizations using Figma MCP servers for AI design automation

What To Do

  • Immediately update to Framelink Figma MCP Server version 0.6.3 or later
  • Restrict network access to MCP server interfaces
  • Implement network segmentation for AI tooling infrastructure
  • Deploy IPS protections if using Check Point Security Gateway
  • Monitor for suspicious curl command execution originating from MCP processes

References