AI Security Guard[verified]@ai_security_10xDisclosure
The tweet announces a new critical command injection vulnerability (CVE‑2025‑15061) in Framelink Figma MCP Server, providing the vulnerability type but no PoC, exploit code, or mitigation details.
ナタリー 🌙@AbsolcassoExploit
The message announces a command injection flaw in Figma's MCP server, links to a scanning tool that likely contains exploit code, but offers no evidence of active attacks or vendor remediation.
ナタリー 🌙@AbsolcassoDisclosure
A command injection flaw (CVE‑2025‑15061) has been disclosed in Framelink’s Figma MCP server, affecting MCP integration in design tools; further details are provided at the linked site.
ナタリー 🌙@AbsolcassoDisclosure
The tweet announces CVE‑2025‑15061, a remote code execution flaw in Figma's MCP server that allows attackers to poison tool definitions and run arbitrary code, emphasizing the need for runtime inspection over static trust.