{"id":"GHSA-9wxg-vf3r-56hc","summary":"OpenZeppelin Contracts Wizard: Line terminators in info.securityContact / info.license can inject lines into generated source","details":"## Summary\n\nThe Contracts Wizard generators printed `info.securityContact` and `info.license` verbatim into a single-line comment of the generated Solidity, Cairo, Stellar/Soroban, and Stylus source without rejecting line terminators. A newline (`\\n` or `\\r\\n`) in either field ends the comment, so the text after it is emitted as source rather than remaining inside the comment — allowing arbitrary declarations to be injected into the generated contract.\n\n## Impact\n\nThis only matters when these fields are filled from input other than the user who will use the generated contract. Normal self-service use does not meet that condition:\n\n- **Web app, AI assistant, and CLI:** the user supplies these fields and uses their own output, so a line break only affects their own contract. (These fields are not URL-derived, so shared links cannot set them.)\n- **Self-hosted API:** same — the end user supplies the options and consumes the result.\n\nThe case that matters is an integration that fills these fields from untrusted input — for example, an MCP agent whose tool arguments are derived from content it processed. There, a newline in the value can add lines to output that otherwise looks like normal Wizard source. Impact is integrity-only; there is no execution on any Wizard service.\n\n## Patches\n\nFixed by rejecting line terminators in `setInfo` — the single code path all surfaces use — so the value can no longer break out of the comment. Upgrade to the patched versions. `@openzeppelin/wizard-confidential` and `@openzeppelin/wizard-uniswap-hooks` reuse this `setInfo` through their `@openzeppelin/wizard` dependency and receive the fix once that dependency is updated to a patched version.","aliases":["CVE-2026-57583"],"modified":"2026-09-15T03:56:01.702706709Z","published":"2026-06-19T17:45:15Z","database_specific":{"severity":"LOW","github_reviewed":true,"github_reviewed_at":"2026-06-19T17:45:15Z","nvd_published_at":null,"cwe_ids":["CWE-116","CWE-94"]},"references":[{"type":"WEB","url":"https://github.com/OpenZeppelin/contracts-wizard/security/advisories/GHSA-9wxg-vf3r-56hc"},{"type":"PACKAGE","url":"https://github.com/OpenZeppelin/contracts-wizard"}],"affected":[{"package":{"name":"@openzeppelin/wizard","ecosystem":"npm","purl":"pkg:npm/%40openzeppelin/wizard"},"ranges":[{"type":"SEMVER","events":[{"introduced":"0"},{"fixed":"0.10.11"}]}],"database_specific":{"last_known_affected_version_range":"\u003c= 0.10.10","source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/06/GHSA-9wxg-vf3r-56hc/GHSA-9wxg-vf3r-56hc.json"}},{"package":{"name":"@openzeppelin/wizard-cairo","ecosystem":"npm","purl":"pkg:npm/%40openzeppelin/wizard-cairo"},"ranges":[{"type":"SEMVER","events":[{"introduced":"0"},{"fixed":"3.0.1"}]}],"database_specific":{"last_known_affected_version_range":"\u003c= 3.0.0","source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/06/GHSA-9wxg-vf3r-56hc/GHSA-9wxg-vf3r-56hc.json"}},{"package":{"name":"@openzeppelin/wizard-stellar","ecosystem":"npm","purl":"pkg:npm/%40openzeppelin/wizard-stellar"},"ranges":[{"type":"SEMVER","events":[{"introduced":"0"},{"fixed":"0.6.2"}]}],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/06/GHSA-9wxg-vf3r-56hc/GHSA-9wxg-vf3r-56hc.json","last_known_affected_version_range":"\u003c= 0.6.1"}},{"package":{"name":"@openzeppelin/wizard-stylus","ecosystem":"npm","purl":"pkg:npm/%40openzeppelin/wizard-stylus"},"ranges":[{"type":"SEMVER","events":[{"introduced":"0"},{"fixed":"0.3.1"}]}],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/06/GHSA-9wxg-vf3r-56hc/GHSA-9wxg-vf3r-56hc.json","last_known_affected_version_range":"\u003c= 0.3.0"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N"}]}