XSS in Figma Plugins: Real Risks and Practical Fixes

Figma plugins feel deceptively safe. A lot of developers assume, “It’s a design tool, not a public website, so XSS probably isn’t a big deal here.” That assumption gets people into trouble fast. Figma plugins are basically little web apps glued onto a privileged plugin runtime. You still have HTML, JavaScript, message passing, user-controlled content, and the usual temptation to throw untrusted strings into innerHTML. That’s enough for XSS. The exact blast radius is different from a normal browser app, but the root problem is the same: untrusted data reaches a dangerous sink and runs as code. ...

October 5, 2026 · 7 min · headertest.com