OpenZeppelin disclosed a code-injection vulnerability in @openzeppelin/wizard that affected versions through 0.10.8, allowing attacker-controlled values in opts.name and opts.uri to be written into generated Hardhat and Foundry example test files without proper escaping. By breaking out of a string literal, a malicious input could inject arbitrary code into the generated project, which would then run when a developer executed test workflows such as npm test or forge test.
The company said the issue was fixed in @openzeppelin/wizard 0.10.9, which now escapes opts.name and opts.uri during test-file generation. OpenZeppelin also said the hosted Contracts Wizard at wizard.openzeppelin.com had already been redeployed with the fix, and that the documented public API was not affected because the vulnerable zipHardhat and zipFoundry functions were not part of the documented public exports; users invoking those functions with externally controlled strings were advised to upgrade.

See affected versions and whether adversaries are exploiting it.
3 events from the most recent confirmed update back to the earliest known activity.
On 2026-05-20, OpenZeppelin published a security advisory for @openzeppelin/wizard versions up to and including 0.10.8 describing code injection in generated Hardhat and Foundry tests via unsanitized opts.name and opts.uri. The advisory recommended upgrading to version 0.10.9 and noted that documented public API users were not affected.
On 2026-05-20, OpenZeppelin released @openzeppelin/wizard version 0.10.9 to address GHSA-4x76-22x2-rx8v. The fix escapes opts.name and opts.uri when generating Hardhat and Foundry test files, and the release notes said the issue affected callers of zipHardhat and zipFoundry.
OpenZeppelin said the hosted Contracts Wizard at wizard.openzeppelin.com had already been redeployed with a fix for a code injection flaw involving unsanitized opts.name and opts.uri in generated Hardhat and Foundry test files. The issue could allow attacker-controlled input to be inserted into generated test code and execute when developers ran tests.
See whether adversaries are exploiting this yet, and where the affected versions run in your environment.
2 references tracked. Mallory keeps watching after this page renders.
github.com
Open sourcegithub.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.