A command injection flaw was recently found in an npm package used to connect Figma to AI agents.

Worrying Figma MCP security flaw could let hackers execute code remotely – here’s how to stay safe
Credit: The original article is published here.