The tokenURI function returns a pre-defined string for all tokens. This could be exploited by an attacker to manipulate the token's metadata or redirect users to malicious websites.
Manual
The contract stores the tokenURI as a constant string variable.
An attacker could exploit a vulnerability in the underlying libraries or functions used to generate the tokenURI to modify its content
The contest is live. Earn rewards by submitting a finding.
This is your time to appeal against judgements on your submissions.
Appeals are being carefully reviewed by our judges.