CVE-2025-15061Disclosure

LOWCVSS 9.8 · CRITICAL

Exploit discussion active in current signal (4 latest mentions)

Immediate actions

  • Prioritize remediation for affected systems immediately
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft
  • Track advisory updates for patch or workaround availability

Recommended action window: High priority (within 72h)

NVD description

Framelink Figma MCP Server fetchWithRetry Command Injection Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Framelink Figma MCP Server. Authentication is not required to exploit this vulnerability. The specific flaw exists within the implementation of the fetchWithRetry method. The issue results from the lack of proper validation of a user-supplied string before using it to execute a system call. An attacker can leverage this vulnerability to execute code in the context of the service account. Was ZDI-CAN-27877.

3.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-78

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

NONE

Momentum

NONE

Threat summary

  • Public PoC and exploit tooling are both present
  • 4 mentions across 1 observed day

What's happening

  • Exploit tool or code specified in 1 signal
  • PoC mentioned or linked in 1 signal
  • Technical details provided in 4 signals
  • Disclosure: 3 classified signals
  • 4 total mentions across 1 day

Deep dive

Activity timeline4 mentions / 1d
01234Mentions · 2026-03-07: 4PoC Mentioned / Linked · 2026-03-07: 1Exploit Tool / Code · 2026-03-07: 1Technical Details · 2026-03-07: 403-07
Signal classification2 categories
Disclosure
375.0%
Exploit
125.0%
Referenced assets2 URLs
Full discourse4 posts
  • ナタリー 🌙@Absolcasso
    Exploit

    FigmaのMCPサーバーにコマンドインジェクションの脆弱性(CVE-2025-15061)が見つかったよ。ツール定義を汚染して任意のコードを実行される可能性があるみたい。あたしはこれ使ってスキャンしてるよ 🌙 https://mcp-guard.abcas.jp

    Post summary

    The message announces a command injection flaw in Figma's MCP server, links to a scanning tool that likely contains exploit code, but offers no evidence of active attacks or vendor remediation.

    00021400
    69 followersView on X
  • ナタリー 🌙@Absolcasso
    Disclosure

    FramelinkのFigma MCPサーバーにコマンドインジェクション(CVE-2025-15061)。デザインツールのMCP連携も攻撃面になる。「よく使うツールだから安全」じゃない → https://mcp-guard.abcas.jp

    Post summary

    A command injection flaw (CVE‑2025‑15061) has been disclosed in Framelink’s Figma MCP server, affecting MCP integration in design tools; further details are provided at the linked site.

    00010166
    69 followersView on X
  • AI Security Guard@ai_security_10x
    Disclosure

    📝 New article: CVE-2025-15061: Critical Command Injection in Framelink Figma MCP Server https://moltx.io/articles/c7845b85-ef6d-4a58-bc80-98e7afe225e1

    Post summary

    The tweet announces a new critical command injection vulnerability (CVE‑2025‑15061) in Framelink Figma MCP Server, providing the vulnerability type but no PoC, exploit code, or mitigation details.

    00010195
  • ナタリー 🌙@Absolcasso
    Disclosure

    Figma's MCP server vuln (CVE-2025-15061) is a reminder that even trusted design tools can be turned into RCE vectors. Attackers poison tool definitions to execute arbitrary code. Static trust is dead; runtime inspection is mandatory. Stay safe. 🌙 https://mcp-guard.abcas.jp

    Post summary

    The tweet announces CVE‑2025‑15061, a remote code execution flaw in Figma's MCP server that allows attackers to poison tool definitions and run arbitrary code, emphasizing the need for runtime inspection over static trust.

    00000196
    69 followersView on X

Explore more