VYPR
High severity8.8GHSA Advisory· Published Aug 6, 2026· Updated Sep 8, 2026

CVE-2026-48054

CVE-2026-48054

Description

OpenZeppelin Contracts Wizardis a web application to interactively build a contract out of components from OpenZeppelin Contracts. Versions prior to 0.10.9 generate a Hardhat test file (test/test.ts) by interpolating user-supplied opts.name (ERC20/ERC721) and opts.uri (ERC1155) directly into TypeScript string literals at zip-hardhat.ts:48 and :50 without any JavaScript string escaping. No authentication is required: an attacker crafts a URL such as https[:]//wizard[.]openzeppelin[.]com/#/erc20?name=");require("child_process").execSync("...");(" and shares it with a developer. When the victim downloads the resulting zip archive and runs npx hardhat test, the injected Node.js code executes with the developer's local OS privileges. Version 0.10.9 fixes the issue.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected packages

Versions sourced from the GitHub Security Advisory.

PackageAffected versionsPatched versions
@openzeppelin/wizardnpm
< 0.10.90.10.9

Affected products

1

Patches

Vulnerability mechanics

References

4

News mentions

0

No linked articles in our index yet.