Command Injection Vulnerability in NellyW8 MCP4EDA Product
CVE-2026-19332
4.8MEDIUM
What is CVE-2026-19332?
A security flaw has been identified in NellyW8 MCP4EDA version 1.0.0, specifically within the functionality of the run_openlane/view_waveform component. The issue arises from improper handling of the design_name and vcd_file parameters, which can be exploited to perform command injection. This vulnerability necessitates local access to the system, allowing an attacker to execute arbitrary commands. Despite being reported early through an issue tracking platform, the vendor has yet to address this critical concern.
Affected Version(s)
MCP4EDA 1.0.0
