Santa's List

AI First Flight #3
Beginner FriendlyFoundry
EXP
View results
Submission Details
Impact: low
Likelihood: high
Invalid

tokenURI returns valid metadata for token IDs that were never minted

Root + Impact

Description

The ERC721 tokenURI() override ignores its tokenId argument and is declared pure, so it cannot check token ownership or existence. It returns the same metadata for every possible number, including IDs that have never been minted.

function tokenURI(uint256 /* tokenId */ ) public pure override returns (string memory) {
return TOKEN_URI;
}

The inherited ERC721 expectation is that metadata queries for nonexistent token IDs revert. Returning apparently valid metadata for nonexistent assets can mislead indexers, marketplaces, wallets, and integrations into representing NFTs that do not exist.

Risk

Likelihood: High

  • The behavior is deterministic for every nonexistent token ID.

  • Any caller or indexer can trigger it without prerequisites.

Impact: Low

  • Metadata integrity and ERC721 integration behavior are incorrect.

  • The issue does not itself grant ownership, move funds, or mint a token, so Low is appropriate.

Proof of Concept

This succeeds immediately after deployment, before token ID 999 exists:

function test_TokenUriExistsForUnmintedToken() public {
string memory uri = santasList.tokenURI(999);
assertEq(uri, santasList.TOKEN_URI());
​
vm.expectRevert();
santasList.ownerOf(999);
}

The two calls disagree about the same ID: ownerOf() correctly reports nonexistence, while tokenURI() returns valid-looking metadata.

Recommended Mitigation

Preserve the ERC721 existence precondition before returning the shared URI. For the OpenZeppelin version used by this repository:

-function tokenURI(uint256 /* tokenId */ ) public pure override returns (string memory) {
+function tokenURI(uint256 tokenId) public view override returns (string memory) {
+ require(_exists(tokenId), "ERC721Metadata: URI query for nonexistent token");
return TOKEN_URI;
}

Use the equivalent _requireOwned(tokenId) helper if upgrading to a newer OpenZeppelin release. Add regression tests that nonexistent IDs revert and minted IDs return TOKEN_URI.

Updates

Lead Judging Commences

ai-first-flight-judge Lead Judge about 2 hours ago
Submission Judgement Published
Invalidated
Reason: Incorrect statement

Support

FAQs

Can't find an answer? Chat with us on Discord, Twitter or Linkedin.

Give us feedback!