Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Sun, 09 Aug 2026 04:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A security vulnerability has been detected in NellyW8 MCP4EDA 1.0.0. Affected by this vulnerability is an unknown functionality of the component run_openlane/view_waveform. The manipulation of the argument design_name/vcd_file leads to command injection. Local access is required to approach this attack. The project was informed of the problem early through an issue report but has not responded yet. | |
| Title | NellyW8 MCP4EDA run_openlane/view_waveform command injection | |
| First Time appeared |
Nellyw8
Nellyw8 mcp4eda |
|
| Weaknesses | CWE-74 CWE-77 |
|
| CPEs | cpe:2.3:a:nellyw8:mcp4eda:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Nellyw8
Nellyw8 mcp4eda |
|
| References |
| |
| Metrics |
cvssV2_0
|
Status: PUBLISHED
Assigner: VulDB
Published:
Updated: 2026-08-09T04:30:10.503Z
Reserved: 2026-08-08T09:55:19.914Z
Link: CVE-2026-19332
No data.
No data.
No data.
OpenCVE Enrichment
Updated: 2026-08-09T06:00:09Z