CVE-2026-19332

Severity CVSS v4.0:
LOW
Type:
CWE-74 Injection
Publication date:
09/08/2026
Last modified:
12/08/2026

Description

A security vulnerability has been detected in NellyW8 MCP4EDA 1.0.0. Affected by this vulnerability is an unknown functionality of the component run_openlane/view_waveform. The manipulation of the argument design_name/vcd_file leads to command injection. Local access is required to approach this attack. The project was informed of the problem early through an issue report but has not responded yet.