What is CVE-2026-19332?
This vulnerability affects the run_openlane/view_waveform component in NellyW8 MCP4EDA 1.0.0, allowing command injection via the design_name/vcd_file arguments. The issue requires local access to exploit, and users should apply vendor-supplied patches or updates to mitigate the risk.
Azərbaycanca: Bu boşluq NellyW8 MCP4EDA 1.0.0 versiyasının run_openlane/view_waveform komponentində aşkarlanıb və design_name/vcd_file arqumentlərinin manipulyasiyası nəticəsində command injection zəifliyinə səbəb olur. Lokal giriş tələb edən bu hücumdan qorunmaq üçün proqram təminatını ən son versiyaya yeniləmək tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-77
FAQ2
What software is affected by CVE-2026-19332?
This vulnerability specifically affects version 1.0.0 of NellyW8 MCP4EDA.
How can users mitigate the risk of CVE-2026-19332?
To mitigate the risk of CVE-2026-19332, users should apply vendor-supplied patches or update the software.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.