Vulnerabilities/

OpenZeppelin Contracts Wizard has Code Injection in Generated Hardhat and Foundry Tests via Unsanitized opts.name / opts

Severity:
High

Description

The OpenZeppelin Contracts Wizard generated Hardhat (test/test.ts) and Foundry (test/<Name>.t.sol) example test files that interpolated user-supplied strings (opts.name, opts.uri) into the test source without escaping.

Recommendation

Update the @openzeppelin/wizard package to the latest compatible version. Followings are version details:

References

Related Issues

Tags:
npm
@openzeppelin/wizard
Anything's wrong? Let us know Last updated on June 11, 2026