PatchSiren

OpenZeppelin CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

MEDIUM OpenZeppelin CVE published 2026-08-13

CVE-2026-73645

A vulnerability in OpenZeppelin Confidential Contracts, an experimental library for developing applications on the Zama fhEVM, could allow users to transfer underlying tokens without receiving corresponding confidential wrapped tokens due to a failure in handling overflowing internal _mint operations. This issue was fixed in version 0.3.1. The vulnerability arises from the ERC7984 contract tracking confid [truncated]

HIGH OpenZeppelin CVE published 2026-08-06

CVE-2026-48054

OpenZeppelin Contracts Wizard, a web application for interactively building contracts from OpenZeppelin Contracts components, is affected by a code injection vulnerability. Versions prior to 0.10.9 generate a Hardhat test file by directly interpolating user-supplied input into TypeScript string literals without proper escaping. This allows attackers to craft malicious URLs that, when downloaded and run, e [truncated]