Concern of Figma McP -Secare Error could let hackers perform code externally – here is how to remain safe


  • CVE-2025-53967 allows the execution of remote code via Figma-Developer-MPC command error
  • Vulnerability derives from unfortunate input transferred to Shell commands using Child_process.exec
  • Users need to upgrade to version 0.6.3 or switch to safer child_process.execile API

A vulnerability has been found on the bridge between Figma and AI agents, which could be used to remotely execute malicious code on compromised final points, experts have warned.

A new security advice published on GitHub says the ‘Figma-Developer-MPC’ NPM package is vulnerable to a command injection error.

Leave a Comment

Your email address will not be published. Required fields are marked *

Scroll to Top