The ERC721 tokenURI() override ignores its tokenId argument and is declared pure, so it cannot check token ownership or existence. It returns the same metadata for every possible number, including IDs that have never been minted.
The inherited ERC721 expectation is that metadata queries for nonexistent token IDs revert. Returning apparently valid metadata for nonexistent assets can mislead indexers, marketplaces, wallets, and integrations into representing NFTs that do not exist.
Likelihood: High
The behavior is deterministic for every nonexistent token ID.
Any caller or indexer can trigger it without prerequisites.
Impact: Low
Metadata integrity and ERC721 integration behavior are incorrect.
The issue does not itself grant ownership, move funds, or mint a token, so Low is appropriate.
This succeeds immediately after deployment, before token ID 999 exists:
The two calls disagree about the same ID: ownerOf() correctly reports nonexistence, while tokenURI() returns valid-looking metadata.
Preserve the ERC721 existence precondition before returning the shared URI. For the OpenZeppelin version used by this repository:
Use the equivalent _requireOwned(tokenId) helper if upgrading to a newer OpenZeppelin release. Add regression tests that nonexistent IDs revert and minted IDs return TOKEN_URI.
The contest is live. Earn rewards by submitting a finding.
Submissions are being reviewed by our AI judge. Results will be available in a few minutes.
View all submissionsThe contest is complete and the rewards are being distributed.