Netskope Threat Labs

SERVER-WEBAPP Framelink Figma MCP Server command injection attempt

IPS-NPA

2 SIDs: 65387, 65388

First seen
May 2026
Last seen
May 2026

Detects an attempt to exploit CVE-2025-53967, a command injection flaw that can run operating system commands on the server in Framelink Figma MCP Server.