Vulnerability Description
Figma Desktop for Windows version 125.6.5 contains a command injection vulnerability in the local plugin loader. An attacker can execute arbitrary OS commands by setting a crafted build field in the plugin's manifest.json. This field is passed to child_process.exec without validation, leading to possible RCE. NOTE: this is disputed by the Supplier because the behavior only allows a local user to attack himself via a local plugin. The local build procedure, which is essential to the attack, is not executed for plugins shared to the Figma Community.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Figma | Desktop | 125.6.5 |
Related Weaknesses (CWE)
References
- https://github.com/shinyColumn/CVE-2025-56803ExploitThird Party Advisory
- https://shinycolumn.notion.site/figma-command-injectionExploitThird Party Advisory
FAQ
What is CVE-2025-56803?
CVE-2025-56803 is a vulnerability with a CVSS score of 8.4 (HIGH). Figma Desktop for Windows version 125.6.5 contains a command injection vulnerability in the local plugin loader. An attacker can execute arbitrary OS commands by setting a crafted build field in the p...
How severe is CVE-2025-56803?
CVE-2025-56803 has been rated HIGH with a CVSS base score of 8.4/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2025-56803?
Check the references section above for vendor advisories and patch information. Affected products include: Figma Desktop.