PatchSiren

nxp-auto-goldvip CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

MEDIUM nxp-auto-goldvip CVE published 2026-08-09

CVE-2026-19359

CVE-2026-19359 is a medium severity vulnerability in gvip up to 1.4.0, caused by improper access controls in the SitewiseCustomFunction of the Lambda Function Handler. The vulnerability has a CVSS score of 5.1 and can be exploited remotely. A fix is available in version 1.15.0. Users of gvip up to version 1.4.0 should be aware of this vulnerability and take steps to upgrade to a fixed version. The project [truncated]