# @radix-ui/react-select@2.3.7 security report (npm)

- Verdict: **No issues** (risk level: safe)
- Scanned: 2026-10-06T14:11:37.000Z
- Files reviewed: 2
- Findings: 3 low severity findings
- Report: https://security.togoder.click/npm/@radix-ui/react-select
- Source: Togoder Security (https://security.togoder.click), AI source-code review

## Summary

Togoder Security scanned the npm package @radix-ui/react-select@2.3.7 on Oct 6, 2026. An AI review of 2 source files produced 3 low severity findings. No malicious behavior, install-time payloads, credential theft or exfiltration were identified.

## Findings

### [low] dangerouslySetInnerHTML

Finding ID: `NPS-CFD1255974DC`

File: `dist/index.mjs`

The SelectViewport component injects a static CSS string via dangerouslySetInnerHTML. The content is a hardcoded constant tied to scrollbar hiding, not user-controlled or dynamically constructed, so it does not present an XSS risk.

### [low] native select prototype manipulation

Finding ID: `NPS-679E8B2B0180`

File: `dist/index.mjs`

SelectBubbleInput retrieves the HTMLSelectElement.prototype value setter and manually dispatches a synthetic 'change' event to synchronize the hidden native select. This is a standard pattern for Radix primitives and does not introduce a security vulnerability.

### [low] dynamic CU.lt

Finding ID: `NPS-A1EFD6DA024D`

File: `dist/index.mjs`

No instances of eval, new Function, dynamic import with computed input, child_process, network exfiltration, credential harvesting, or lifecycle/install-time code were found in the analyzed file.

## Files reviewed

- `dist/index.js` (safe): No malicious patterns detected; this is the standard Radix UI Select component bundle with no data exfiltration, credential harvesting, obfuscated payloads, or process spawning.
- `dist/index.mjs` (safe): This is a legitimate Radix UI Select component implementation with no malicious patterns; only expected DOM manipulation patterns were observed.

AI analysis is guidance, not a guarantee. Methodology: https://security.togoder.click/methodology
