OpenZeppelin Confidential Contracts Vulnerability: Malicious ERC-7984 Token Can Extract Private Data
A vulnerability in OpenZeppelin's Confidential Contracts, specifically in the `VestingWalletConfidential` component, allows a malicious ERC-7984 token to extract private data from the vesting wallet. The vulnerability has a CVSS score of 7.1 and has been patched in versions v0.5.2, v0.4.2, and v0.3.2. Users should update to a patched version to prevent exploitation.