Web Application Vulnerability in OpenZeppelin Contracts Wizard Affecting Multiple Components
CVE-2026-57583

3.3LOW

Key Information:

Vendor
CVE Published:
14 September 2026

What is CVE-2026-57583?

The OpenZeppelin Contracts Wizard, a tool for building contracts interactively, has a vulnerability where certain sensitive fields, such as info.securityContact and info.license, are printed verbatim into comments in the generated code. This concern arises primarily when the integration of untrusted input populates these fields, which could lead to improper disclosures if users consume the affected source. This impacts the integrity of the generated code but does not affect typical usage scenarios involving self-service web applications, AI assistants, or command-line interfaces, which do not cross trust boundaries. This issue has been resolved in versions 0.10.11, 3.0.1, 0.6.2, and 0.3.1.

Affected Version(s)

contracts-wizard < 0.10.11

wizard < 0.10.11

wizard-cairo < 3.0.1

References

CVSS V3.1

Score:
3.3
Severity:
LOW
Confidentiality:
None
Integrity:
Low
Availability:
None
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.