Command Injection Vulnerability in NellyW8 MCP4EDA Product
CVE-2026-19332

4.8MEDIUM

Key Information:

Vendor

Nellyw8

Status
Vendor
CVE Published:
9 August 2026

What is CVE-2026-19332?

A security flaw has been identified in NellyW8 MCP4EDA version 1.0.0, specifically within the functionality of the run_openlane/view_waveform component. The issue arises from improper handling of the design_name and vcd_file parameters, which can be exploited to perform command injection. This vulnerability necessitates local access to the system, allowing an attacker to execute arbitrary commands. Despite being reported early through an issue tracking platform, the vendor has yet to address this critical concern.

Affected Version(s)

MCP4EDA 1.0.0

References

CVSS V4

Score:
4.8
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Local
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

gongyanyu04 (VulDB User)
VulDB CNA Team
.