VDB
Sign up
MEDIUM6.5

PYSEC-2026-890

OpenZeppelin Contracts for Cairo account cannot process transactions on Goerli

Quick fix

PYSEC-2026-890 — openzeppelin-cairo-contracts: upgrade to the fixed version with the command below.

pip install --upgrade 'openzeppelin-cairo-contracts>=0.2.1'

Details

### Impact This vulnerability affects all accounts (vanilla and ethereum flavors) in the [v0.2.0 release of OpenZeppelin Contracts for Cairo](https://github.com/OpenZeppelin/cairo-contracts/releases/tag/v0.2.0), which are not whitelisted on StarkNet mainnet, so only goerli deployments of v0.2.0 accounts are affected.

This faulty behavior is not observed in [StarkNet's testing framework](https://github.com/starkware-libs/cairo-lang/blob/master/src/starkware/starknet/testing/starknet.py), so don't rely on it passing to detect this issue on custom accounts.

### Patches This bug has been patched in [v0.2.1](https://github.com/OpenZeppelin/cairo-contracts/releases/tag/v0.2.1).

### References The issue is detailed in https://github.com/OpenZeppelin/cairo-contracts/issues/386.

### For more information If you have any questions or comments about this advisory: * Open an issue in [the Contracts for Cairo repo](https://github.com/OpenZeppelin/cairo-contracts/issues/new/choose) * Email us at [security@openzeppelin.com](mailto:security@openzeppelin.com)

Are you affected?

Enter the version of the package you're using.

Affected packages

PyPI/openzeppelin-cairo-contracts
Introduced in: 0Fixed in: 0.2.1
Fixpip install --upgrade 'openzeppelin-cairo-contracts>=0.2.1'

References