PatchSiren

NellyW8 CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

LOW NellyW8 CVE published 2026-08-09

CVE-2026-19332

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-08-09T05:16:51.030Z and has not been modified since then. A command injection vulnerability exists in NellyW8 MCP4EDA 1.0.0, specifically in the run_openlane/view_waveform component. The vulnerability is triggered by manipulating the design_name/vcd_file argument. Local access is required for a potenti [truncated]