Description
OpenZeppelin Contracts Wizard is a web application to interactively build a contract out of components from OpenZeppelin Contracts. Prior to @openzeppelin/wizard 0.10.11, @openzeppelin/wizard-cairo 3.0.1, @openzeppelin/wizard-stellar 0.6.2, and @openzeppelin/wizard-stylus 0.3.1, the setInfo code path prints info.securityContact and info.license verbatim into single-line comments in generated Solidity, Cairo, Stellar/Soroban, and Stylus source. A line terminator ends the comment and causes following input to be emitted as source declarations. Exploitation requires an integration to populate these fields from untrusted input and a user to consume the generated source; normal self-service web, AI assistant, CLI, and self-hosted API use does not cross that trust boundary, shared links cannot set the fields, and no code executes on a Wizard service. This issue affects generated-source integrity only and is fixed in versions 0.10.11, 3.0.1, 0.6.2, and 0.3.1 of the respective packages.
Published: 2026-09-14
Score: 3.3 Low
EPSS: < 1% Very Low
KEV: No
Impact: Source code integrity compromise in generated smart contracts
Action: Apply Patch
AI Analysis

Impact

The vulnerability arises when user‑supplied values for info.securityContact or info.license are inserted verbatim into single‑line comments of the generated Solidity, Cairo, Stellar/Soroban, or Stylus source code. This vulnerability is an example of CWE-116 (Improper Encoding) and CWE-94 (Dynamic Code Execution). A line terminator in these fields ends the comment, causing subsequent input to be interpreted as actual source declarations. The resulting injected code becomes part of the contract that a developer may compile and deploy, potentially altering contract logic or permissions. Affected systems include OpenZeppelin’s Contracts Wizard web application and its packages @openzeppelin/wizard, @openzeppelin/wizard-cairo, @openzeppelin/wizard-stellar, and @openzeppelin/wizard-stylus. Versions prior to @openzeppelin/wizard 0.10.11, @openzeppelin/wizard-cairo 3.0.1, @openzeppelin/wizard-stellar 0.6.2, and @openzeppelin/wizard-stylus 0.3.1 are vulnerable. The issue is limited to the source that is generated by the wizard; the wizard itself does not execute the injected code. The risk is moderate as indicated by a CVSS score of 3.3. Exploitation requires an integration that sets these fields from untrusted input and a user or automated process that consumes the generated source. Typical self‑service use, shared links, and standard API use do not cross the necessary trust boundary. The vulnerability is not listed as a known exploited vulnerability, and no external exploit code has been reported. Nonetheless, the injection could lead to the deployment of contracts with unintended behavior.

Affected Systems

OpenZeppelin Contracts Wizard and its associated packages @openzeppelin/wizard, @openzeppelin/wizard-cairo, @openzeppelin/wizard-stellar, and @openzeppelin/wizard-stylus. Vulnerable versions are those released before @openzeppelin/wizard 0.10.11, @openzeppelin/wizard-cairo 3.0.1, @openzeppelin/wizard-stellar 0.6.2, and @openzeppelin/wizard-stylus 0.3.1.

Risk and Exploitability

The CVSS score is 3.3, indicating moderate severity. The EPSS score is 0.00131, indicating a very low but nonzero probability of exploitation, and the vulnerability is not listed in the CISA KEV catalog. Because the attacker must supply untrusted data consume the generated source, exploitation is contingent on a misconfigured integration or a vector is limited to the generation process; no code on the wizard service is executed. As such, the likelihood of widespread exploitation is low, but mitigations should still be implemented.

Generated by OpenCVE AI on September 20, 2026 at 23:29 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Update to @openzeppelin/wizard 0.10.11 or newer, @openzeppelin/wizard-cairo 3.0.1 or newer, @openzeppelin/wizard-stellar 0.6.2 or newer, and @openzeppelin/wizard-stylus 0.3.1 or newer.
  • Ensure that any integration or form that populates info.securityContact or info.license sanitizes input to remove or escape line terminators before passing the data to the wizard.
  • Disable or restrict automated population of info.securityContact and info.license from untrusted sources, and verify that only trusted inputs are allowed.

Generated by OpenCVE AI on September 20, 2026 at 23:29 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 17 Sep 2026 20:30:00 +0000

Type Values Removed Values Added
First Time appeared Openzeppelin
Openzeppelin contracts-wizard
Openzeppelin wizard
Openzeppelin wizard-cairo
Openzeppelin wizard-stellar
Openzeppelin wizard-stylus
Vendors & Products Openzeppelin
Openzeppelin contracts-wizard
Openzeppelin wizard
Openzeppelin wizard-cairo
Openzeppelin wizard-stellar
Openzeppelin wizard-stylus

Mon, 14 Sep 2026 21:00:00 +0000

Type Values Removed Values Added
Description OpenZeppelin Contracts Wizard is a web application to interactively build a contract out of components from OpenZeppelin Contracts. Prior to @openzeppelin/wizard 0.10.11, @openzeppelin/wizard-cairo 3.0.1, @openzeppelin/wizard-stellar 0.6.2, and @openzeppelin/wizard-stylus 0.3.1, the setInfo code path prints info.securityContact and info.license verbatim into single-line comments in generated Solidity, Cairo, Stellar/Soroban, and Stylus source. A line terminator ends the comment and causes following input to be emitted as source declarations. Exploitation requires an integration to populate these fields from untrusted input and a user to consume the generated source; normal self-service web, AI assistant, CLI, and self-hosted API use does not cross that trust boundary, shared links cannot set the fields, and no code executes on a Wizard service. This issue affects generated-source integrity only and is fixed in versions 0.10.11, 3.0.1, 0.6.2, and 0.3.1 of the respective packages.
Title OpenZeppelin Contracts Wizard: Line terminators in info.securityContact / info.license can inject lines into generated source
Weaknesses CWE-116
CWE-94
References
Metrics cvssV3_1

{'score': 3.3, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Subscriptions

Openzeppelin Contracts-wizard Wizard Wizard-cairo Wizard-stellar Wizard-stylus
cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published:

Updated: 2026-09-14T19:06:58.101Z

Reserved: 2026-06-24T18:49:56.209Z

Link: CVE-2026-57583

cve-icon Vulnrichment

Updated: 2026-09-14T19:06:51.766Z

cve-icon NVD

Status : Deferred

Published: 2026-09-14T18:17:58.720

Modified: 2026-09-30T19:57:08.043

Link: CVE-2026-57583

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-20T23:30:07Z

Weaknesses
  • CWE-116

    Improper Encoding or Escaping of Output

  • CWE-94

    Improper Control of Generation of Code ('Code Injection')