IA Squad
SearchPT

@openzeppelin/wizard

js · @openzeppelin/wizardCritical

@openzeppelin/wizard: Code injection in generated test files via unescaped strings

The OpenZeppelin Contracts Wizard generated example test files that interpolated user-supplied strings without escaping, allowing

12 Jun 2026 · act now