Impact
The vulnerability arises when user‑supplied values for info.securityContact or info.license are inserted verbatim into single‑line comments of the generated Solidity, Cairo, Stellar/Soroban, or Stylus source code. This vulnerability is an example of CWE-116 (Improper Encoding) and CWE-94 (Dynamic Code Execution). A line terminator in these fields ends the comment, causing subsequent input to be interpreted as actual source declarations. The resulting injected code becomes part of the contract that a developer may compile and deploy, potentially altering contract logic or permissions. Affected systems include OpenZeppelin’s Contracts Wizard web application and its packages @openzeppelin/wizard, @openzeppelin/wizard-cairo, @openzeppelin/wizard-stellar, and @openzeppelin/wizard-stylus. Versions prior to @openzeppelin/wizard 0.10.11, @openzeppelin/wizard-cairo 3.0.1, @openzeppelin/wizard-stellar 0.6.2, and @openzeppelin/wizard-stylus 0.3.1 are vulnerable. The issue is limited to the source that is generated by the wizard; the wizard itself does not execute the injected code. The risk is moderate as indicated by a CVSS score of 3.3. Exploitation requires an integration that sets these fields from untrusted input and a user or automated process that consumes the generated source. Typical self‑service use, shared links, and standard API use do not cross the necessary trust boundary. The vulnerability is not listed as a known exploited vulnerability, and no external exploit code has been reported. Nonetheless, the injection could lead to the deployment of contracts with unintended behavior.
Affected Systems
OpenZeppelin Contracts Wizard and its associated packages @openzeppelin/wizard, @openzeppelin/wizard-cairo, @openzeppelin/wizard-stellar, and @openzeppelin/wizard-stylus. Vulnerable versions are those released before @openzeppelin/wizard 0.10.11, @openzeppelin/wizard-cairo 3.0.1, @openzeppelin/wizard-stellar 0.6.2, and @openzeppelin/wizard-stylus 0.3.1.
Risk and Exploitability
The CVSS score is 3.3, indicating moderate severity. The EPSS score is 0.00131, indicating a very low but nonzero probability of exploitation, and the vulnerability is not listed in the CISA KEV catalog. Because the attacker must supply untrusted data consume the generated source, exploitation is contingent on a misconfigured integration or a vector is limited to the generation process; no code on the wizard service is executed. As such, the likelihood of widespread exploitation is low, but mitigations should still be implemented.
OpenCVE Enrichment