Description
The Contracts Wizard generators printed info.securityContact and info.license verbatim into a single-line comment of the generated Solidity, Cairo, Stellar/Soroban, and Stylus source without rejecting line terminators.
Recommendation
Update the @openzeppelin/wizard-cairo package to the latest compatible version. Followings are version details:
- Affected version(s): <= 3.0.0
- Patched version(s): 3.0.1
References
Could your website be exposed too?
SmartScanner can check your website for OpenZeppelin Contracts Wizard: Line terminators in info.securityContact / info.license can inject lines into generated s - @openzeppelin/wizard-cairo and gives you actionable findings to investigate.
Start a free scanRelated Issues
- OpenZeppelin Contracts Wizard: Line terminators in info.securityContact / info.license can inject lines into generated s - @openzeppelin/wizard-stellar - Vulnerability
- OpenZeppelin Contracts Wizard: Line terminators in info.securityContact / info.license can inject lines into generated s - @openzeppelin/wizard-stylus - Vulnerability
- OpenZeppelin Contracts Wizard: Line terminators in info.securityContact / info.license can inject lines into generated s - Vulnerability
- OpenZeppelin Contracts Wizard has Code Injection in Generated Hardhat and Foundry Tests via Unsanitized opts.name / opts - CVE-2026-48054


