@openzeppelin/wizard
js · @openzeppelin/wizardCritical
@openzeppelin/wizard: Code injection in generated test files via unescaped strings
The OpenZeppelin Contracts Wizard generated example test files that interpolated user-supplied strings without escaping, allowing
12 Jun 2026 · act now