openzeppelin-cairo-contracts
Library for secure smart contract development written in Cairo
Activity
- Latest release
- 3y ago
- Total releases
- 12
- Cadence
- ~21 days
- Last 12 months
- 0
Details
- License
- MIT
- First release
- Mar 23, 2022
| Version | Released | |
|---|---|---|
0.6.1
patch
| ||
0.6.0
minor
1 CVE
CVE-2023-23940
PYSEC-2023-39
GHSA-626q-v9j4-mcp4
Feb 03, 2023
OpenZeppelin Contracts for Cairo is a library for secure smart contract development written in Cairo for StarkNet, a decentralized ZK Rollup. Affected versions
0.2.0
0.2.1
0.3.0
0.3.1
0.3.2
0.4.0
0.4.0b0
0.5.0
0.5.1
0.6.0
Fixed in
0.6.1
References Updated Feb 22, 2026 · Source: OSV.dev | ||
0.5.1
patch
1 CVE
CVE-2023-23940
PYSEC-2023-39
GHSA-626q-v9j4-mcp4
Feb 03, 2023
OpenZeppelin Contracts for Cairo is a library for secure smart contract development written in Cairo for StarkNet, a decentralized ZK Rollup. Affected versions
0.2.0
0.2.1
0.3.0
0.3.1
0.3.2
0.4.0
0.4.0b0
0.5.0
0.5.1
0.6.0
Fixed in
0.6.1
References Updated Feb 22, 2026 · Source: OSV.dev | ||
0.5.0
minor
1 CVE
CVE-2023-23940
PYSEC-2023-39
GHSA-626q-v9j4-mcp4
Feb 03, 2023
OpenZeppelin Contracts for Cairo is a library for secure smart contract development written in Cairo for StarkNet, a decentralized ZK Rollup. Affected versions
0.2.0
0.2.1
0.3.0
0.3.1
0.3.2
0.4.0
0.4.0b0
0.5.0
0.5.1
0.6.0
Fixed in
0.6.1
References Updated Feb 22, 2026 · Source: OSV.dev | ||
0.4.0
minor
1 CVE
CVE-2023-23940
PYSEC-2023-39
GHSA-626q-v9j4-mcp4
Feb 03, 2023
OpenZeppelin Contracts for Cairo is a library for secure smart contract development written in Cairo for StarkNet, a decentralized ZK Rollup. Affected versions
0.2.0
0.2.1
0.3.0
0.3.1
0.3.2
0.4.0
0.4.0b0
0.5.0
0.5.1
0.6.0
Fixed in
0.6.1
References Updated Feb 22, 2026 · Source: OSV.dev | ||
0.4.0b0
pre
1 CVE
CVE-2023-23940
PYSEC-2023-39
GHSA-626q-v9j4-mcp4
Feb 03, 2023
OpenZeppelin Contracts for Cairo is a library for secure smart contract development written in Cairo for StarkNet, a decentralized ZK Rollup. Affected versions
0.2.0
0.2.1
0.3.0
0.3.1
0.3.2
0.4.0
0.4.0b0
0.5.0
0.5.1
0.6.0
Fixed in
0.6.1
References Updated Feb 22, 2026 · Source: OSV.dev | ||
0.3.2
patch
1 CVE
CVE-2023-23940
PYSEC-2023-39
GHSA-626q-v9j4-mcp4
Feb 03, 2023
OpenZeppelin Contracts for Cairo is a library for secure smart contract development written in Cairo for StarkNet, a decentralized ZK Rollup. Affected versions
0.2.0
0.2.1
0.3.0
0.3.1
0.3.2
0.4.0
0.4.0b0
0.5.0
0.5.1
0.6.0
Fixed in
0.6.1
References Updated Feb 22, 2026 · Source: OSV.dev | ||
0.3.1
patch
1 CVE
CVE-2023-23940
PYSEC-2023-39
GHSA-626q-v9j4-mcp4
Feb 03, 2023
OpenZeppelin Contracts for Cairo is a library for secure smart contract development written in Cairo for StarkNet, a decentralized ZK Rollup. Affected versions
0.2.0
0.2.1
0.3.0
0.3.1
0.3.2
0.4.0
0.4.0b0
0.5.0
0.5.1
0.6.0
Fixed in
0.6.1
References Updated Feb 22, 2026 · Source: OSV.dev | ||
0.3.0
minor
1 CVE
CVE-2023-23940
PYSEC-2023-39
GHSA-626q-v9j4-mcp4
Feb 03, 2023
OpenZeppelin Contracts for Cairo is a library for secure smart contract development written in Cairo for StarkNet, a decentralized ZK Rollup. Affected versions
0.2.0
0.2.1
0.3.0
0.3.1
0.3.2
0.4.0
0.4.0b0
0.5.0
0.5.1
0.6.0
Fixed in
0.6.1
References Updated Feb 22, 2026 · Source: OSV.dev | ||
0.2.1
patch
1 CVE
CVE-2023-23940
PYSEC-2023-39
GHSA-626q-v9j4-mcp4
Feb 03, 2023
OpenZeppelin Contracts for Cairo is a library for secure smart contract development written in Cairo for StarkNet, a decentralized ZK Rollup. Affected versions
0.2.0
0.2.1
0.3.0
0.3.1
0.3.2
0.4.0
0.4.0b0
0.5.0
0.5.1
0.6.0
Fixed in
0.6.1
References Updated Feb 22, 2026 · Source: OSV.dev | ||
0.2.0
minor
2 CVEs
CVE-2022-31153
PYSEC-2026-890
GHSA-8mjr-jr5h-q2xr
Jul 06, 2026
OpenZeppelin Contracts for Cairo account cannot process transactions on Goerli
6.5
/ 10
Medium
Network
Low
Low
None
Unchanged
None
None
High
ImpactThis vulnerability affects all accounts (vanilla and ethereum flavors) in the v0.2.0 release of OpenZeppelin Contracts for Cairo, which are not whitelisted on StarkNet mainnet, so only goerli deployments of v0.2.0 accounts are affected. This faulty behavior is not observed in StarkNet's testing framework, so don't rely on it passing to detect this issue on custom accounts. PatchesThis bug has been patched in v0.2.1. ReferencesThe issue is detailed in https://github.com/OpenZeppelin/cairo-contracts/issues/386. For more informationIf you have any questions or comments about this advisory:
Affected versions
0.1.0
0.2.0
Fixed in
0.2.1
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2023-23940
PYSEC-2023-39
GHSA-626q-v9j4-mcp4
Feb 03, 2023
OpenZeppelin Contracts for Cairo is a library for secure smart contract development written in Cairo for StarkNet, a decentralized ZK Rollup. Affected versions
0.2.0
0.2.1
0.3.0
0.3.1
0.3.2
0.4.0
0.4.0b0
0.5.0
0.5.1
0.6.0
Fixed in
0.6.1
References Updated Feb 22, 2026 · Source: OSV.dev | ||
0.1.0
initial
1 CVE
CVE-2022-31153
PYSEC-2026-890
GHSA-8mjr-jr5h-q2xr
Jul 06, 2026
OpenZeppelin Contracts for Cairo account cannot process transactions on Goerli
6.5
/ 10
Medium
Network
Low
Low
None
Unchanged
None
None
High
ImpactThis vulnerability affects all accounts (vanilla and ethereum flavors) in the v0.2.0 release of OpenZeppelin Contracts for Cairo, which are not whitelisted on StarkNet mainnet, so only goerli deployments of v0.2.0 accounts are affected. This faulty behavior is not observed in StarkNet's testing framework, so don't rely on it passing to detect this issue on custom accounts. PatchesThis bug has been patched in v0.2.1. ReferencesThe issue is detailed in https://github.com/OpenZeppelin/cairo-contracts/issues/386. For more informationIf you have any questions or comments about this advisory:
Affected versions
0.1.0
0.2.0
Fixed in
0.2.1
References
Updated Jul 07, 2026 · Source: OSV.dev |