CVE-2022-31153
MEDIUMOpenZeppelin Contracts for Cairo <0.2.0 - Info Disclosure
Title source: llmDescription
OpenZeppelin Contracts for Cairo is a library for contract development written in Cairo for StarkNet, a decentralized ZK Rollup. Version 0.2.0 is vulnerable to an error that renders account contracts unusable on live networks. This issue affects all accounts (vanilla and ethereum flavors) in the v0.2.0 release of OpenZeppelin Contracts for Cairo, which are not whitelisted on StarkNet mainnet. Only goerli deployments of v0.2.0 accounts are affected. This faulty behavior is not observed in StarkNet's testing framework. This bug has been patched in v0.2.1.
Scores
CVSS v3
6.5
EPSS
0.0111
EPSS Percentile
78.2%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
CISA SSVC
Vulnrichment
Exploitation
poc
Automatable
no
Technical Impact
partial
Details
CWE
CWE-863
CWE-664
Status
published
Products (2)
openzeppelin/contracts
0.2.0
pypi/openzeppelin-cairo-contracts
0 - 0.2.1PyPI
Published
Jul 15, 2022
Tracked Since
Feb 18, 2026