OpenZeppelin Contracts Wizard: Line terminators in info.securityContact / info.license can inject lines into generated s - @openzeppelin/wizard-stylus
- Severity:
- Low
Description
The Contracts Wizard generators printed info.securityContact and info.license verbatim into a single-line comment of the generated Solidity, Cairo, Stellar/Soroban, and Stylus source without rejecting line terminators.
Recommendation
Update the @openzeppelin/wizard-stylus package to the latest compatible version. Followings are version details:
- Affected version(s): <= 0.3.0
- Patched version(s): 0.3.1
References
Related Issues
- OpenZeppelin Contracts Wizard: Line terminators in info.securityContact / info.license can inject lines into generated s - @openzeppelin/wizard-cairo - Vulnerability
- OpenZeppelin Contracts Wizard: Line terminators in info.securityContact / info.license can inject lines into generated s - @openzeppelin/wizard-stellar - Vulnerability
- OpenZeppelin Contracts Wizard: Line terminators in info.securityContact / info.license can inject lines into generated s - Vulnerability
- OpenZeppelin Contracts Wizard has Code Injection in Generated Hardhat and Foundry Tests via Unsanitized opts.name / opts - CVE-2026-48054
You might also like:
- Tags:
- npm
- @openzeppelin/wizard-stylus
Anything's wrong? Let us know Last updated on June 19, 2026


