Web Application Vulnerability in OpenZeppelin Contracts Wizard Affecting Multiple Components
CVE-2026-57583
What is CVE-2026-57583?
The OpenZeppelin Contracts Wizard, a tool for building contracts interactively, has a vulnerability where certain sensitive fields, such as info.securityContact and info.license, are printed verbatim into comments in the generated code. This concern arises primarily when the integration of untrusted input populates these fields, which could lead to improper disclosures if users consume the affected source. This impacts the integrity of the generated code but does not affect typical usage scenarios involving self-service web applications, AI assistants, or command-line interfaces, which do not cross trust boundaries. This issue has been resolved in versions 0.10.11, 3.0.1, 0.6.2, and 0.3.1.
Affected Version(s)
contracts-wizard < 0.10.11
wizard < 0.10.11
wizard-cairo < 3.0.1
