A vulnerability in OpenZeppelin Confidential Contracts, an experimental library for developing applications on the Zama fhEVM, could allow users to transfer underlying tokens without receiving corresponding confidential wrapped tokens due to a failure in handling overflowing internal _mint operations. This issue was fixed in version 0.3.1. The vulnerability arises from the ERC7984 contract tracking confid [truncated]
OpenZeppelin Contracts Wizard, a web application for interactively building contracts from OpenZeppelin Contracts components, is affected by a code injection vulnerability. Versions prior to 0.10.9 generate a Hardhat test file by directly interpolating user-supplied input into TypeScript string literals without proper escaping. This allows attackers to craft malicious URLs that, when downloaded and run, e [truncated]