All 2 CVE vulnerabilities found in contracts-wizard, with AI-generated Chinese analysis, references, and POCs.
Vendor: OpenZeppelin
| CVE ID | Title | CVSS | Severity | Published |
|---|---|---|---|---|
| CVE-2026-57583 | OpenZeppelin Contracts Wizard: Line terminators in info.securityContact / info.license can inject lines into generated source CWE-94 | 3.3 | Low | 2026-09-14 |
| CVE-2026-48054 | OpenZeppelin Contracts Wizard has Code Injection in Generated Hardhat and Foundry Tests via Unsanitized opts.name / opts.uri CWE-94 | 8.8 | High | 2026-08-06 |
All 2 known CVE vulnerabilities affecting contracts-wizard with full Chinese analysis, references, and POCs where available.