cbcvebase.
CVE-2023-26488
published 2023-03-03

CVE-2023-26488: OpenZeppelin Contracts is a library for secure smart contract development. The ERC721Consecutive contract designed for minting NFTs in batches does not update…

PriorityP432medium6.5CVSS 3.1
AVNACLPRLUINSUCNIHAN
EPSS
0.71%
49.5th percentile
OpenZeppelin Contracts is a library for secure smart contract development. The ERC721Consecutive contract designed for minting NFTs in batches does not update balances when a batch has size 1 and consists of a single token. Subsequent transfers from the receiver of that token may overflow the balance as reported by `balanceOf`. The issue exclusively presents with batches of size 1. The issue has been patched in 4.8.2.

Affected

5 ranges
VendorProductVersion rangeFixed in
openzeppelincontracts>= 4.8.0 < 4.8.24.8.2
openzeppelincontracts>= 4.8.0 < 4.8.24.8.2
openzeppelincontracts-upgradeable>= 4.8.0 < 4.8.24.8.2
openzeppelincontracts_upgradeable>= 4.8.0 < 4.8.24.8.2
openzeppelinopenzeppelin-contracts
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.