figma-developer-mcp
Give your coding agent access to your Figma data. Implement designs in any framework in one-shot.
Installing this server brings 133 third-party packages inside your agent's trust boundary (16 direct). This is attack surface, not a vulnerability count — it does not affect the grade above.
Findings (1)
- HIGH
VULN_KNOWN— GHSA-gxw4-4fc5-9gr5: figma-developer-mcp vulnerable to command injection in get_figma_data tool. See https://osv.dev/vulnerability/GHSA-gxw4-4fc5-9gr5
Embed this badge
[](https://vulnrable.com/mcp/figma-developer-mcp/) Automated registry-metadata scan; not a code audit. Rescanned on each site deploy.