LOW
NellyW8
CVE published 2026-08-09
CVE-2026-19332
AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-08-09T05:16:51.030Z and has not been modified since then. A command injection vulnerability exists in NellyW8 MCP4EDA 1.0.0, specifically in the run_openlane/view_waveform component. The vulnerability is triggered by manipulating the design_name/vcd_file argument. Local access is required for a potenti [truncated]