A new security advisory published on GitHub says the ‘figma-developer-mpc’ npm package is vulnerable to a command injection ...