Unauthenticated command injection RCE in Framelink Figma and Ollama MCP servers
Two disclosed vulnerabilities (CVE-2025-15061 and CVE-2025-15063) allow remote, unauthenticated attackers to execute arbitrary code on installations of the Framelink Figma MCP Server and the Ollama MCP Server, due to unvalidated user-supplied strings passed into system calls in the fetchWithRetry and execAsync methods respectively. Code executes in the context of the service account.
Disclosed 23 January 2026 · Record updated 13 September 2026
Impact
Remote attackers without authentication can run arbitrary code on affected MCP server installations, in the context of the service account.
Our coverage
No articles linked to this incident yet.
Sources
- nvd.nist.govhttps://nvd.nist.gov/vuln/detail/CVE-2025-15061
- nvd.nist.govhttps://nvd.nist.gov/vuln/detail/CVE-2025-15063
