Get all your news in one place.
100's of premium titles.
One app.
Start reading
TechRadar
TechRadar
Sead Fadilpašić

Worrying Framelink MCP security flaw could let hackers execute code remotely - here's how to stay safe

Code Skull.
  • CVE-2025-53967 allows remote code execution via figma-developer-mpc command injection flaw
  • Vulnerability stems from unvalidated input passed to shell commands using child_process.exec
  • Users should upgrade to version 0.6.3 or switch to safer child_process.execFile API

A vulnerability has been found on the bridge between Figma and AI agents which could be used to remotely execute malicious code on compromised endpoints, experts have warned.

Sign up to read this article
Read news from 100's of titles, curated specifically for you.
Already a member? Sign in here
Related Stories
Top stories on inkl right now
One subscription that gives you access to news from hundreds of sites
Already a member? Sign in here
Our Picks
Fourteen days free
Download the app
One app. One membership.
100+ trusted global sources.