GHSA-5vp3-v4hc-gx76

    Dashboard / Vulnerabilities / GHSA-5vp3-v4hc-gx76

    GHSA-5vp3-v4hc-gx76

    Published: 15 Sept 2021Last Modified: 8 Jul 2026

    Summary: UUPSUpgradeable vulnerability in @openzeppelin/contracts

    Details: ### Impact Upgradeable contracts using `UUPSUpgradeable` may be vulnerable to an attack affecting uninitialized implementation contracts. We will update this advisory with more information soon. ### Patches A fix is included in version 4.3.2 of `@openzeppelin/contracts` and `@openzeppelin/contracts-upgradeable`. ### Workarounds Initialize implementation contracts using `UUPSUpgradeable` by invoking the initializer function (usually called `initialize`). An example is provided [in the forum](https://forum.openzeppelin.com/t/security-advisory-initialize-uups-implementation-contracts/15301). ### References [Post-mortem](https://forum.openzeppelin.com/t/uupsupgradeable-vulnerability-post-mortem/15680). ### For more information If you have any questions or comments about this advisory, or need assistance executing the mitigation, email us at [email protected].

    Affected packages

    Package

    Name: @openzeppelin/contracts

    Purl: pkg:npm/%40openzeppelin/contracts

    Affected ranges

    Type: SEMVER

    Events:

    Introduced- 4.1.0
    Fixed -4.3.2

    Affected versions

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High
    GHSA-5vp3-v4hc-gx76 | CVE-DB