PYSEC-2026-890
OpenZeppelin Contracts for Cairo account cannot process transactions on Goerli
Quick fix
PYSEC-2026-890 — openzeppelin-cairo-contracts: upgrade to the fixed version with the command below.
pip install --upgrade 'openzeppelin-cairo-contracts>=0.2.1'Details
### Impact This vulnerability affects all accounts (vanilla and ethereum flavors) in the [v0.2.0 release of OpenZeppelin Contracts for Cairo](https://github.com/OpenZeppelin/cairo-contracts/releases/tag/v0.2.0), which are not whitelisted on StarkNet mainnet, so only goerli deployments of v0.2.0 accounts are affected.
This faulty behavior is not observed in [StarkNet's testing framework](https://github.com/starkware-libs/cairo-lang/blob/master/src/starkware/starknet/testing/starknet.py), so don't rely on it passing to detect this issue on custom accounts.
### Patches This bug has been patched in [v0.2.1](https://github.com/OpenZeppelin/cairo-contracts/releases/tag/v0.2.1).
### References The issue is detailed in https://github.com/OpenZeppelin/cairo-contracts/issues/386.
### For more information If you have any questions or comments about this advisory: * Open an issue in [the Contracts for Cairo repo](https://github.com/OpenZeppelin/cairo-contracts/issues/new/choose) * Email us at [security@openzeppelin.com](mailto:security@openzeppelin.com)
Are you affected?
Enter the version of the package you're using.
Affected packages
0Fixed in: 0.2.1pip install --upgrade 'openzeppelin-cairo-contracts>=0.2.1'References
- https://github.com/OpenZeppelin/cairo-contracts/security/advisories/GHSA-8mjr-jr5h-q2xr[WEB]
- https://nvd.nist.gov/vuln/detail/CVE-2022-31153[ADVISORY]
- https://github.com/OpenZeppelin/cairo-contracts/issues/386[WEB]
- https://github.com/OpenZeppelin/cairo-contracts/pull/387[WEB]
- https://github.com/OpenZeppelin/cairo-contracts/commit/2cd60279c3332285d47edf9ee3888b71257acdc9[WEB]
- https://github.com/OpenZeppelin/cairo-contracts[PACKAGE]
- https://github.com/OpenZeppelin/cairo-contracts/blob/release-0.2.0/src/openzeppelin/account/library.cairo#L203[WEB]
- https://github.com/OpenZeppelin/cairo-contracts/releases/tag/v0.2.1[WEB]
- https://github.com/pypa/advisory-database/tree/main/vulns/openzeppelin-cairo-contracts-test/PYSEC-2022-43143.yaml[WEB]
- https://pypi.org/project/openzeppelin-cairo-contracts[PACKAGE]
- https://github.com/advisories/GHSA-8mjr-jr5h-q2xr[ADVISORY]