The smart contracts relies on outdated versions of the OpenZeppelin contracts library, which are known to contain vulnerabilities.
Given the presence of known vulnerabilities in the current @openzeppelin/contracts version, it is advisable to update to at least @openzeppelin/contracts@5.0.1 to address these issues and enhance the contract's security
Openzeppelin/contracts-upgradeable known vulnerabilities
Using contracts with known vulnerabilities can lead to a wide range of attacks, depending on the nature of the vulnerabilities.
Manual Review
Consider updating to @openzeppelin/contracts@5.0.1 and @openzeppelin/contracts-upgradeable@5.0.1
The contest is live. Earn rewards by submitting a finding.
This is your time to appeal against judgements on your submissions.
Appeals are being carefully reviewed by our judges.