THREAT OPS › Threat News › [NVD] CVE-2026-19332 (MEDIUM 5.3) — A security vulnerability has been detected in NellyW8 MCP4EDA 1.0.0. Affected by this vulnerability is an unknown functionality of the component run_openlane/view_waveform. The manipulation of the argument design_name/vcd_file leads to command injection. Local access is required
[NVD] CVE-2026-19332 (MEDIUM 5.3) — A security vulnerability has been detected in NellyW8 MCP4EDA 1.0.0. Affected by this vulnerability is an unknown functionality of the component run_openlane/view_waveform. The manipulation of the argument design_name/vcd_file leads to command injection. Local access is required
CVE-2026-19332 CVSS: 5.3 MEDIUM Published: 2026-08-09T05:16:51.030
A security vulnerability has been detected in NellyW8 MCP4EDA 1.0.0. Affected by this vulnerability is an unknown functionality of the component run_openlane/view_waveform. The manipulation of the argument design_name/vcd_file leads to command injection. Local access is required to approach this attack. The project was informed of
Indicators of compromise
- CVE-2026-19332cve
Original source: https://nvd.nist.gov/vuln/detail/CVE-2026-19332