CVE-2026-57583: OpenZeppelin Contracts Wizard: Line terminators in info.securityContact / info.license can inject lines into generated source
OpenZeppelin Contracts Wizard is a web application to interactively build a contract out of components from OpenZeppelin Contracts. Prior to @openzeppelin/wizard 0.10.11, @openzeppelin/wizard-cairo 3.0.1, @openzeppelin/wizard-stellar 0.6.2, and @openzeppelin/wizard-stylus 0.3.1, the setInfo code path prints info.securityContact and info.license verbatim into single-line comments in generated Solidity, Cairo, Stellar/Soroban, and Stylus source. A line terminator ends the comment and causes following input to be emitted as source declarations. Exploitation requires an integration to populate these fields from untrusted input and a user to consume the generated source; normal self-service web, AI assistant, CLI, and self-hosted API use does not cross that trust boundary, shared links cannot set the fields, and no code executes on a Wizard service. This issue affects generated-source integrity only and is fixed in versions 0.10.11, 3.0.1, 0.6.2, and 0.3.1 of the respective packages.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
@openzeppelin/wizardto a version that resolves this vulnerability.Fixed in 0.10.11 - Upgrade
Upgrade
@openzeppelin/wizard-cairoto a version that resolves this vulnerability.Fixed in 3.0.1 - Upgrade
Upgrade
@openzeppelin/wizard-stellarto a version that resolves this vulnerability.Fixed in 0.6.2 - Upgrade
Upgrade
@openzeppelin/wizard-stylusto a version that resolves this vulnerability.Fixed in 0.3.1
Event History
Frequently Asked Questions
Who is realistically exposed to this issue?
Integrations that populate securityContact or license from untrusted input are exposed if users may consume the generated source. Normal self-service web, AI assistant, CLI, and self-hosted API usage does not cross the required trust boundary, and shared links cannot set these fields.
What does an attacker need to exploit it?
An attacker needs a way to supply line terminators and subsequent content through the securityContact or license fields via an integration that trusts untrusted input. A user must then consume the generated source containing the injected declarations.
Does exploitation execute code on a Wizard service?
No. The issue affects the integrity of generated source code only; no code executes on a Wizard service.
What versions remediate the issue?
Use @openzeppelin/wizard 0.10.11, @openzeppelin/wizard-cairo 3.0.1, @openzeppelin/wizard-stellar 0.6.2, or @openzeppelin/wizard-stylus 0.3.1, as applicable.
What can be done before upgrading?
Do not populate the securityContact or license fields from untrusted input. Treat generated source that includes values from those fields as untrusted and review it before use.