AI description
CVE-2025-15060 identifies a command injection vulnerability within the Framelink Figma MCP Server. This flaw specifically resides in the implementation of the `fetchWithRetry` method. The vulnerability stems from a lack of proper validation of user-supplied strings before they are used to execute a system call. This oversight allows remote attackers to execute arbitrary code on affected installations of the Framelink Figma MCP Server without requiring authentication. An attacker can leverage this to execute code in the context of the service account.
- Description
- claude-hovercraft executeClaudeCode Command Injection Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of claude-hovercraft. Authentication is not required to exploit this vulnerability. The specific flaw exists within the implementation of the executeClaudeCode method. The issue results from the lack of proper validation of a user-supplied string before using it to execute a system call. An attacker can leverage this vulnerability to execute code in the context of the service account. Was ZDI-CAN-27785.
- Source
- zdi-disclosures@trendmicro.com
- NVD status
- Awaiting Analysis
CVSS 3.0
- Type
- Secondary
- Base score
- 9.8
- Impact score
- 5.9
- Exploitability score
- 3.9
- Vector string
- CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
- Severity
- CRITICAL
- zdi-disclosures@trendmicro.com
- CWE-78
- Hype score
- Not currently trending
[CVE-2025-15060: CRITICAL] Critical vulnerability in claude-hovercraft's executeClaudeCode method allows remote attackers to execute arbitrary code without authentication, posing serious security risks. Patc...#cve,CVE-2025-15060,#cybersecurity https://t.co/WjobIraavg
@CveFindCom
16 Mar 2026
106 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
CVE-2025-15060 claude-hovercraft executeClaudeCode Command Injection Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on aff… https://t.co/ya9WOLltAq
@CVEnew
13 Mar 2026
164 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
🚨 CVE-2025-15060: claude-hovercraft executeClaudeC... Unauthenticated RCE via command injection in executeClaudeCode method - CVSS 9.8 speaks volumes about trivial exploitat... https://t.co/K5N97vX7j5 #netsec #vulnerability #CVE #sysadmin #zeroday
@0dayPublishing
13 Mar 2026
141 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
[ZDI-26-124|CVE-2025-15060] claude-hovercraft executeClaudeCode Command Injection Remote Code Execution Vulnerability (CVSS 9.8; Credit: Peter Girnus (@gothburz) of Trend Research) https://t.co/0Ium1xKDRC
@TheZDIBugs
25 Feb 2026
3022 Impressions
4 Retweets
10 Likes
5 Bookmarks
0 Replies
0 Quotes