CVE-2026-19332
MEDIUM
NVD
CVSS Score
5.3
Severity
MEDIUM
Published
Aug 09, 2026
Vendor
unknown
Description
A security vulnerability has been detected in NellyW8 MCP4EDA 1.0.0. Affected by this vulnerability is an unknown functionality of the component run_openlane/view_waveform. The manipulation of the argument design_name/vcd_file leads to command injection. Local access is required to approach this attack. The project was informed of the problem early through an issue report but has not responded yet.