PatchSiren

OpenZeppelin CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

HIGH OpenZeppelin CVE published 2026-08-06

CVE-2026-48054

OpenZeppelin Contracts Wizard, a web application for interactively building contracts from OpenZeppelin Contracts components, is affected by a code injection vulnerability. Versions prior to 0.10.9 generate a Hardhat test file by directly interpolating user-supplied input into TypeScript string literals without proper escaping. This allows attackers to craft malicious URLs that, when downloaded and run, e [truncated]