CVE-2026-48054
Description
OpenZeppelin Contracts Wizardis a web application to interactively build a contract out of components from OpenZeppelin Contracts. Versions prior to 0.10.9 generate a Hardhat test file (test/test.ts) by interpolating user-supplied opts.name (ERC20/ERC721) and opts.uri (ERC1155) directly into TypeScript string literals at zip-hardhat.ts:48 and :50 without any JavaScript string escaping. No authentication is required: an attacker crafts a URL such as https[:]//wizard[.]openzeppelin[.]com/#/erc20?name=");require("child_process").execSync("...");(" and shares it with a developer. When the victim downloads the resulting zip archive and runs npx hardhat test, the injected Node.js code executes with the developer's local OS privileges. Version 0.10.9 fixes the issue.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
@openzeppelin/wizardnpm | < 0.10.9 | 0.10.9 |
Affected products
1- Range: <= 0.10.8
Patches
Vulnerability mechanics
References
4- github.com/advisories/GHSA-4x76-22x2-rx8vghsaADVISORY
- github.com/OpenZeppelin/contracts-wizard/commit/ec12c44f8d9e0491eba31037f95b36e98ec58b5fnvdWEB
- github.com/OpenZeppelin/contracts-wizard/releases/tag/%40openzeppelin%2Fwizard%400.10.9nvdWEB
- github.com/OpenZeppelin/contracts-wizard/security/advisories/GHSA-4x76-22x2-rx8vnvdWEB
News mentions
0No linked articles in our index yet.