CVE-2026-48054
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Summary
OpenZeppelin Contracts Wizardis a web application to interactively build a contract out of components from OpenZeppelin Contracts. Versions prior to 0.10.9 generate a Hardhat test file (test/test.ts) by interpolating user-supplied opts.name (ERC20/ERC721) and opts.uri (ERC1155) directly into TypeScript string literals at zip-hardhat.ts:48 and :50 without any JavaScript string escaping. No authentication is required: an attacker crafts a URL such as https[:]//wizard[.]openzeppelin[.]com/#/erc20?name=");require("child_process").execSync("...");(" and shares it with a developer. When the victim downloads the resulting zip archive and runs npx hardhat test, the injected Node.js code executes with the developer's local OS privileges. Version 0.10.9 fixes the issue.
Affected Software
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| OpenZeppelin | contracts-wizard | < 0.10.9 | affected |
Weaknesses
- CWE-94: CWE-94: Improper Control of Generation of Code ('Code Injection')
References
- https://github.com/OpenZeppelin/contracts-wizard/security/advisories/GHSA-4x76-22x2-rx8v
- https://github.com/OpenZeppelin/contracts-wizard/commit/ec12c44f8d9e0491eba31037f95b36e98ec58b5f
- https://github.com/OpenZeppelin/contracts-wizard/releases/tag/%40openzeppelin%2Fwizard%400.10.9
Feedback
Was this page helpful?
Glad to hear it! Please tell us how we can improve.
Sorry to hear that. Please tell us how we can improve.