Summary
Togoder Security scanned the npm package ajv@6.15.0 on Oct 6, 2026. An AI review of 44 source files produced 2 high, 4 medium, 5 low severity findings. The overall verdict is medium: the findings flag risky but common patterns (dynamic code, unsafe defaults, broad file or network access) rather than confirmed malware.
Findings 11
Dynamic code execution via new Function
NPS-54E801DBDF0D
The compiler builds a JavaScript source string from user-provided JSON schema and executes it via new Function(...). This is the core design of Ajv (it is a code-generating validator), so it is expected behavior, but it means arbitrary schema input is turned into executable code. If schema content is not strictly controlled, it could enable code injection leading to arbitrary code execution in the host process.
Custom keyword code execution
NPS-C9D94C935DE8
User-supplied custom keywords (rule.definition.compile/macro/inline/validate) are invoked and their results are inserted into the generated function. This is by-design for Ajv, but it means the module will execute arbitrary functions provided in the schema options, which is a code execution vector if untrusted sources can influence keyword definitions.
Generated code via regexp construction
NPS-B2AAAE258B85
Patterns from schemas are embedded into new RegExp(...) calls inside the generated source. Malicious or pathological regex patterns supplied through schemas can result in ReDoS, and if not properly escaped (toQuotedString is used, which is decent) could cause issues in the generated function scope.
Custom code injection through processCode option
NPS-B4D0C18BBFB7
If opts.processCode is supplied by the consumer application, the compiled source string is passed through it before being executed. This is a legitimate Ajv extension point, but it allows arbitrary transformation of the generated code, which could be abused if options are attacker-controlled.
Dynamic module loading with computed paths
NPS-B01BA8277D55
The script constructs paths to package.json and the package main entry using command-line arguments and dynamically requires them. This can load and execute arbitrary modules from within node_modules based on the provided pkg argument, potentially executing untrusted code if the argument is controlled by an attacker.
Build-time code execution
NPS-5374C52800AD
This is a build script that executes at build time (likely via npm run scripts). It uses browserify and uglify-js to bundle and minify code. The dynamic require of package.json and the package main module means that any code in the required modules will execute during the build process. If a malicious package is referenced via the pkg argument, its code will run.
Dynamic code generation
NPS-E8B7FB0EE434
Generates JavaScript code strings that are later compiled/executed (via new Function) containing console.log or user-supplied $comment function calls, which is inherent to ajv's code generation design but could be abused if schema data is untrusted.
Potential data exposure via logging
NPS-F43FE5C5383B
When opts.$comment is true, the generated validator will console.log the schema comment value, potentially leaking sensitive information present in schemas if logging is enabled.
File system writes outside package scope
NPS-C2F87467C27F
The script writes minified bundle output and source maps to a 'dist' directory relative to the script's parent directory. While not inherently malicious, it writes outside the immediate script directory and could overwrite files if the package name or path is manipulated.
File system manipulation within package scope
NPS-C4F45D7EBBFB
The script creates a 'dotjs' directory and writes compiled template files to it. The paths are resolved relative to the package's lib directory or provided arguments, which is typical for build scripts and does not escape package scope.
Dynamic code generation via template compilation
NPS-AD28D3976CDA
The script uses the 'dot' template engine to compile .jst templates into JavaScript functions. This is a build-time operation and does not involve eval or dynamic execution of untrusted input at runtime. The generated code is written to files, not executed directly.
Files reviewed
| File | Verdict | What the reviewer saw |
|---|---|---|
| lib/compile/index.js | medium | This file is Ajv's schema-to-function compiler and legitimately uses new Function to generate validators, which is expected for the library but constitutes a powerful dynamic code execution surface that must be carefully sandboxed by consumers. |
| lib/dotjs/comment.js | medium | Legitimate ajv code-generation helper that produces validator code; no malicious exfiltration, credential harvesting, or backdoor patterns detected, though it emits dynamic code and optional logging based on configuration. |
| scripts/bundle.js | medium | The script is a build utility that dynamically loads and bundles packages based on command-line arguments, which could be abused to execute arbitrary code from node_modules if the arguments are attacker-controlled. |
| .tonic_example.js | safe | No malicious patterns detected |
| lib/ajv.js | safe | No malicious patterns detected; the file is a legitimate Ajv JSON schema validator module with no data exfiltration, dynamic code execution, or suspicious system interactions. |
| lib/cache.js | safe | Cleared by Jev triage; no further analysis needed |
| lib/compile/async.js | safe | No malicious patterns detected; the code implements asynchronous schema loading for Ajv with proper error handling and no external data exfiltration, dynamic code execution, or process spawning. |
| lib/compile/equal.js | safe | Cleared by Jev triage; no further analysis needed |
| lib/compile/error_classes.js | safe | Cleared by Jev triage; no further analysis needed |
| lib/compile/formats.js | safe | No malicious patterns detected |
| lib/compile/resolve.js | safe | No malicious patterns detected; the code is a standard JSON schema $ref resolver for Ajv with no network, filesystem, process, or dynamic code execution concerns. |
| lib/compile/rules.js | safe | Cleared by Jev triage; no further analysis needed |
| lib/compile/schema_obj.js | safe | Cleared by Jev triage; no further analysis needed |
| lib/compile/ucs2length.js | safe | Cleared by Jev triage; no further analysis needed |
| lib/compile/util.js | safe | Cleared by Jev triage; no further analysis needed |
| lib/data.js | safe | Cleared by Jev triage; no further analysis needed |
| lib/definition_schema.js | safe | Cleared by Jev triage; no further analysis needed |
| lib/dotjs/_limit.js | safe | This is a legitimate ajv JSON schema validator code generation module for limit keywords, with no malicious patterns detected. |
| lib/dotjs/_limitItems.js | safe | No malicious patterns detected; this is a legitimate code-generation module from the ajv JSON schema validator that only emits validation logic strings. |
| lib/dotjs/_limitLength.js | safe | No malicious patterns detected; the file is a standard Ajv JSON schema validator code generator for length constraints. |
| lib/dotjs/_limitProperties.js | safe | The code is a standard JSON schema validator code generator for minProperties/maxProperties with no malicious patterns detected. |
| lib/dotjs/allOf.js | safe | No malicious patterns detected; the code is a legitimate JSON Schema allOf validator code generator. |
| lib/dotjs/anyOf.js | safe | This is a standard code-generation module from the Ajv JSON schema validator, with no malicious patterns or suspicious behavior detected. |
| lib/dotjs/const.js | safe | This file is a legitimate part of the Ajv JSON schema validation library that generates code for the 'const' keyword; no malicious patterns, network calls, credential harvesting, or dynamic code execution were detected. |
| lib/dotjs/contains.js | safe | The code is a standard JSON Schema 'contains' keyword validator generator from the Ajv library with no malicious patterns, network activity, credential access, or dynamic code execution. |
Show 19 more files
| File | Verdict | What the reviewer saw |
|---|---|---|
| lib/dotjs/custom.js | safe | This is a legitimate code generation module from the ajv JSON schema validator library that generates validation code for custom keywords, with no malicious patterns detected. |
| lib/dotjs/dependencies.js | safe | No malicious patterns detected; this file is a standard code generator for JSON Schema 'dependencies' validation in the ajv library. |
| lib/dotjs/enum.js | safe | This is a legitimate Ajv JSON schema validator code generator for the 'enum' keyword with no malicious patterns, network access, process spawning, or credential harvesting. |
| lib/dotjs/format.js | safe | No malicious patterns detected; the code is a standard JSON Schema format validator code generator. |
| lib/dotjs/if.js | safe | This is a legitimate code generation module from the Ajv JSON Schema validator library that produces validation code strings without any malicious patterns. |
| lib/dotjs/index.js | safe | Cleared by Jev triage; no further analysis needed |
| lib/dotjs/items.js | safe | This is standard Ajv JSON Schema validation code generation for the 'items' keyword, with no malicious patterns such as data exfiltration, credential harvesting, obfuscation, network calls, or command execution. |
| lib/dotjs/multipleOf.js | safe | This is a legitimate JSON Schema validator code generator for the 'multipleOf' keyword from Ajv, with no malicious patterns detected. |
| lib/dotjs/not.js | safe | This is a legitimate code generation module from the ajv JSON schema validator that constructs validation code strings without any malicious patterns such as network, filesystem, process, or dynamic code execution abuse. |
| lib/dotjs/oneOf.js | safe | This file is a legitimate part of the Ajv JSON schema validator, generating validation code for the 'oneOf' keyword without any malicious patterns. |
| lib/dotjs/pattern.js | safe | This is legitimate ajv JSON Schema validator code generation for the pattern keyword; no malicious patterns detected. |
| lib/dotjs/properties.js | safe | No malicious patterns detected; this is a legitimate part of the ajv JSON schema validator code generator for 'properties' keyword validation. |
| lib/dotjs/propertyNames.js | safe | This is a legitimate code generation module for the ajv JSON schema validator that generates validation code strings without any malicious patterns. |
| lib/dotjs/ref.js | safe | This is a legitimate code generator from Ajv (JSON Schema validator) for handling $ref references; it contains no malicious patterns such as data exfiltration, credential harvesting, obfuscation, or unauthorized system access. |
| lib/dotjs/required.js | safe | The file is a legitimate code-generation module from the ajv JSON schema validator library that builds validation code strings for the 'required' keyword without any malicious patterns such as exfiltration, dynamic execution of untrusted input, or system-level operations. |
| lib/dotjs/uniqueItems.js | safe | No malicious patterns detected; this is a legitimate code generator for JSON Schema uniqueItems validation. |
| lib/dotjs/validate.js | safe | This is a legitimate code generator from Ajv's dotjs validation module with no malicious patterns such as data exfiltration, credential harvesting, obfuscation, backdoors, or file system manipulation. |
| lib/keyword.js | safe | No malicious patterns detected; the file is a standard Ajv keyword management module with no data exfiltration, credential harvesting, obfuscation, or dynamic code execution. |
| scripts/compile-dots.js | safe | The script is a build tool for compiling doT templates into JavaScript functions, with no malicious patterns such as data exfiltration, credential harvesting, or backdoor installation. |
Affected version ranges
None of the 2 scanned versions of ajv are flagged high or critical. The latest scanned version, 8.20.0, is medium risk. Only versions we have scanned are listed; unscanned versions between them are not covered.
| Versions | Verdict | Count | Range | Top findings |
|---|---|---|---|---|
| 8.20.0 | Needs review | 1 | 8.20.0 | Dynamic code execution; Code generation from external input |
| 8.11.0 โ 8.17.1 | Not scanned | 2 | >=8.11.0 <=8.17.1 | |
| 6.15.0 | Needs review | 1 | 6.15.0 | Dynamic code execution via new Function; Custom keyword code execution |
| 6.12.6 | Not scanned | 1 | 6.12.6 |
Full list, including published versions not scanned yet: version ranges API.
Scanned versions of ajv
Frequently asked questions
Is ajv safe to use?
No confirmed malware was found in ajv@6.15.0, but the review flagged 2 high, 4 medium, 5 low severity findings for risky patterns worth checking before you rely on it.
Does ajv contain malware?
No malware was identified in ajv@6.15.0 when Togoder Security scanned it on Oct 6, 2026. A new version can still introduce malicious code, so scan the exact versions in your lockfile.
How was ajv checked?
Togoder Security downloaded the published npm package and had an AI model read its 44 source files, looking for install scripts, credential access, network exfiltration, obfuscation, backdoors and crypto-wallet theft. The results are cached by file hash and shown here.
How do I scan ajv together with the rest of my dependencies?
Upload your lockfile at https://security.togoder.click/scan or call the API documented at https://security.togoder.click/api-docs. Files that have already been scanned, like the ones in ajv@6.15.0, cost nothing.