Impact
OpenZeppelin Contracts Wizard is a web application to interactively build a contract out of components from OpenZeppelin Contracts. Versions prior to 0.10.9 generate a Hardhat test file (test/test.ts) by interpolating user‑supplied opts.name (ERC20/ERC721) and opts.uri (ERC1155) directly into TypeScript string:48 and :50 without any JavaScript string escaping. No authentication is required; an attacker can craft a malicious URL such as https://wizard.openzeppelin.com/#/erc20?name="");require("child_process").execSync("...");(" and share it with a developer. When the victim downloads the resulting zip archive and runs npx hardhat test, the injected Node.js code executes with the developer's local OS privileges. This flaw is a classic code injection (CWE‑94).
Affected Systems
OpenZeppelin Contracts Wizard, deployed as a web application by OpenZeppelin, is the affected product. All releases prior to version 0.10.9 carry this flaw. The vulnerability is triggered by unescaped user inputs during test file generation, irrespective of the contract type chosen (ERC20, ERC721, ERC1155). Developers who use earlier releases and download the generated test archives are at risk. Updating to 0.10.9 or later removes the code injection path.
Risk and Exploitability
The CVSS score of 8.8 classifies the issue as high severity, reflecting the potential for remote code execution with local system privileges. Because the wizard is publicly can construct a malicious URL that embeds arbitrary Node.js code and easily distribute it to unsuspecting developers. When the victim runs the included test file, the code executes as the invoking user. The EPSS score of < 1% indicates a very low exploitation probability, but the open‑browser nature of the application still suggests a potential risk. The vulnerability is not listed in CISA’s KEV catalog, but the ease of creating and sharing the attack activity.
OpenCVE Enrichment
Github GHSA