HIGH
OpenZeppelin
CVE published 2026-08-06
CVE-2026-48054
OpenZeppelin Contracts Wizard, a web application for interactively building contracts from OpenZeppelin Contracts components, is affected by a code injection vulnerability. Versions prior to 0.10.9 generate a Hardhat test file by directly interpolating user-supplied input into TypeScript string literals without proper escaping. This allows attackers to craft malicious URLs that, when downloaded and run, e [truncated]