GHSA-92x2-9gq9-2w2vLowCVSS 5.3
A security vulnerability has been detected in NellyW8 MCP4EDA 1.0.0. Affected by this...
🔗 CVE IDs covered (1)
📋 Description
A security vulnerability has been detected in NellyW8 MCP4EDA 1.0.0. Affected by this vulnerability is an unknown functionality of the component run_openlane/view_waveform. The manipulation of the argument design_name/vcd_file leads to command injection. Local access is required to approach this attack. The project was informed of the problem early through an issue report but has not responded yet.
🔗 References (8)
- https://nvd.nist.gov/vuln/detail/CVE-2026-19332
- https://github.com/NellyW8/MCP4EDA/issues/3
- https://github.com/NellyW8/MCP4EDA
- https://vuldb.com/cve/CVE-2026-19332
- https://vuldb.com/submit/865255
- https://vuldb.com/vuln/387168
- https://vuldb.com/vuln/387168/cti
- https://github.com/advisories/GHSA-92x2-9gq9-2w2v