Summary
Togoder Security scanned the npm package zod@4.6.5 on Oct 6, 2026. An AI review of 375 source files produced 1 critical, 3 high, 12 medium, 46 low severity findings. At least one finding describes dangerous behavior such as code that runs at install time, credential access or data exfiltration. Do not install this version until you have reviewed the findings below.
Findings 62
Dynamic code execution
NPS-9534A8F558A8
The compile() method uses Function constructor (new F(...Object.keys(this.closed), ...)) to dynamically compile and execute a function from the document's content and closed-over arguments. This is equivalent to eval/new Function and can execute arbitrary code at runtime. If an attacker can control this.content, this.args, or this.closed (e.g., via deserialization or untrusted input), this leads to remote code execution.
Dynamic code execution via new Function
NPS-5F5E411E3391
The code uses new Function (aliased as F) with dynamically generated JavaScript source code built from schema definitions. While this is core to the AOT compilation design of this validation library, dynamic code generation is a high-risk pattern that can be abused if attacker-controlled values reach the codegen path. Notably, the numericOperand() function contains an explicit comment acknowledging this risk: bounds reaching generated source verbatim could allow arbitrary statement injection if types are not enforced. The author mitigates this by validating that bounds are finite numbers before emitting them, but this remains a dangerous pattern requiring careful review.
Dynamic code execution
NPS-22B097E9EAFF
write() accepts functions and invokes them with the Doc instance (arg(this, { execution: "sync" }) and arg(this, { execution: "async" })). Combined with compile(), this forms a dynamic code generation pipeline where user-supplied callbacks can inject arbitrary strings into the compiled function body.
Encoded/obfuscated payload construction
NPS-ADAE75B39B3B
The compile() method builds a function string by interpolating this.closed keys, this.args, and this.content directly into a function body template. This pattern (return function (${args}) { ... }) is a common vector for code injection when any of these inputs are attacker-controlled.
dynamic code execution
NPS-464DC8B143DD
The module imports and invokes a compiler (./v4/core/compile.cjs) that, per the accompanying comments, may generate code via new Function. The shim respects globalConfig.jitless to avoid eval in CSP/no-eval environments, which indicates dynamic code generation is part of the design. This is a legitimate JIT/compilation feature but is a potential vector for code execution if the compiler is compromised or fed untrusted schema definitions.
top-level side effect on import
NPS-2F72A1B28FC3
The file mutates core.globalConfig.postProcessor at module evaluation time and is intended to be imported for side effects. This globally alters parsing behavior for all schemas in the process, including those from other libraries, without explicit opt-in beyond the import statement. Any code importing this module changes runtime semantics process-wide.
Dynamic code execution
NPS-8FADB9BF8F4A
The module builds validator functions via new Function(...) (const F = Function; const factory = new F(...constantNames, factoryCode)). While this is the documented purpose of the AOT compiler (generating a fast-path parser from a Zod schema), it is dynamic code execution. The generated source is built from schema definitions, and the code explicitly guards against source-injection via numericOperand (which rejects non-number bounds because a string bound would be emitted verbatim into generated source). This is a legitimate, defensively-guarded use, but it remains a new Function sink that warrants review in a supply-chain context.
Dynamic code execution
NPS-23A524B6FD8E
The compile() method uses new Function(...) to construct and execute a function from string content stored in this.content and closure names from this.closed. While this appears to be a legitimate code-generation mechanism (similar to template engines), dynamic code execution via the Function constructor can be abused to run arbitrary code if the Doc content is influenced by untrusted input, and it bypasses CSP and static analysis.
Dynamic code execution via constructor
NPS-81A99AEED74D
The module uses core.$constructor and a chain of dynamically constructed check functions. While not directly malicious in this file, the heavy reliance on runtime function construction and prototype manipulation (inst._zod.check = ...) makes behavior dependent on external definitions in core.cjs, regexes.cjs, and util.cjs. This pattern is used by zod v4 for validation but is also a common obfuscation/behavior-injection vector if any of the source modules are tampered with.
Use of eval-like constructor / CSP bypass surface
NPS-EC0A20358DF4
const F = Function; followed by new F(...constantNames, factoryCode) is an alias for the Function constructor, i.e. implicit eval. This is intrinsic to the compiler's purpose, but security reviewers should note it executes dynamically constructed code in the host realm and can be blocked or risky under strict CSP environments; the code catches this as ZodCompileUnsupportedError and falls back to the runtime parser.
Dynamic code execution
NPS-98DDC92F7429
The file generates JavaScript source code at runtime and executes it via new Function(...). This is core to the AOT compiler design (Zod compile fast path), but new Function is a dynamic code execution primitive. The generated code embeds user-supplied callbacks, regex patterns, bounds, and literal values as hoisted constants or inline source. While the code includes backstops such as numericOperand() type checking and util.esc() escaping to mitigate source injection, any flaw in those guards could allow arbitrary code execution because generated source is constructed from schema definitions. The options.debug path also attaches generated code to fn.code.
Potential code injection via interpolated values in generated source
NPS-A9D2ADC677B0
Multiple codegen paths interpolate schema-derived values directly into generated JavaScript source using template literals (e.g., def.value}n, ${prefix.length}, ${accessor}[${util.esc(k)}]). util.esc is used for string escaping in some places, but other interpolations rely on the caller having validated types. The numericOperand guard is a backstop rather than a complete defense. If schema construction paths (JSON Schema import, programmatic mutation) bypass these checks, arbitrary code execution in the generated function is possible.
Dynamic code generation as core mechanism
NPS-994058829AFD
The compileFn function builds a factory via new Function(...constantNames, factoryCode) and executes it. This means user-supplied schema definitions and callbacks are hoisted into generated code and executed. While this is the intended design of a compiler, it substantially expands the attack surface: any bug in the codegen escaping or type-checking logic becomes a code execution vulnerability.
Global mutable configuration hook
NPS-7CCF318D51C5
The code defines and reads a global object globalThis.__zod_globalConfig and exposes a config() function that allows any code to mutate global configuration. More notably, the schema constructor function _ invokes globalThis.__zod_globalConfig?.postProcessor on every constructed schema instance. Any other module in the same process can install a postProcessor that receives every created schema object, giving arbitrary third-party code a hook to inspect and tamper with all Zod schema instances at runtime. This is an undocumented global side-effect and an implicit extension point that could be abused by malicious packages to intercept or mutate schema objects.
Use of Function constructor
NPS-DDBFCB1597C7
The code explicitly uses 'const F = Function;' and then 'new F(...)' to generate executable code. While the content is generated internally from writes to the Doc instance, any external input that reaches the write() method could lead to arbitrary code execution when compile() is called.
Dynamic code execution
NPS-81D7292E02B0
The compile() method uses the Function constructor to create a new function from the accumulated content string. This is a form of dynamic code execution equivalent to eval, which can be dangerous if the content is influenced by untrusted input.
import-time side effects
NPS-BFE94B36FC5D
This file is a side-effect-only module that, upon import, mutates core.globalConfig.postProcessor and monkey-patches inst._zod.run on every schema constructed afterward. It runs top-level code at import time, modifying global behavior of the zod library. While documented and intentional, this kind of global monkey-patching in a package can surprise consumers and alter runtime semantics (e.g., silently replacing the parser with a compiled version).
runtime behavior modification
NPS-2349F20DDBB5
The postProcessor wraps and replaces inst._zod.run with a shim that conditionally swaps in compiled execution paths. If compilation fails, it silently falls back to the original runtime. This is not malicious per se, but the pattern of globally intercepting schema execution could be abused in a supply-chain compromise to alter validation results (e.g., skipping checks) if the underlying compile module were tampered with.
module export freezing
NPS-F28446128293
The 'seal-cjs-exports' IIFE converts getters to fixed values and calls Object.freeze(exports), preventing downstream modification of the module's exports. This is defensive/anti-tampering and not malicious, but it does make the module harder to patch or audit at runtime.
dynamic code execution surface
NPS-DF59DB34AC3C
The module installs a global postProcessor that invokes compile() on schemas. The code explicitly references JIT compilation and guards against new Function via the jitless config, indicating that the compiler generates functions dynamically. While the guard mitigates CSP bypass, this module still triggers dynamic code generation at parse time for any schema constructed after import, which is a significant attack surface if the compiler has flaws.
global state mutation / monkey-patching
NPS-B3D8D244E841
The postProcessor replaces inst._zod.run on schema instances with a shim, and stores __originalRun on the function object. This is a form of runtime monkey-patching that modifies shared library behavior. While the code comments explain the rationale, it can cause subtle interactions (e.g., double-wrapping, recursion guard via compiling flag) that may be exploitable or cause unexpected behavior in downstream consumers.
Dynamic RegExp construction
NPS-4BBC2F11AEBF
User-supplied JSON Schema pattern and patternProperties values are passed directly to new RegExp(...) without validation or escaping. While not malicious itself, this could expose consumers to ReDoS or catastrophic backtracking if untrusted schemas are converted. It is a normal part of implementing JSON Schema semantics, not a security backdoor.
Prototype-pollution hardening
NPS-B01B2E299773
The code explicitly uses assignProp to write __proto__ keys as own properties instead of through the inherited setter, and guards Object.entries/keys usage. This is defensive, not malicious.
JSON round-trip normalization
NPS-2FBED41CF6EE
JSON.parse(JSON.stringify(schema)) is used to normalize input, which is a deliberate defense against cyclic structures, getters, and Proxies. No dynamic evaluation is involved.
Reflection and runtime schema introspection
NPS-1B00C9F3B31E
The compiler reflects over arbitrary user-supplied schemas and callbacks, hoisting user functions (def.fn, def.transform, def.catchValue, def.getter, check._zod.check, tx) into generated closures and invoking them. Errors thrown by these callbacks are intentionally propagated (throwAsync, transform helpers). This matches documented behavior but means any executable code attached to a schema will run during validation.
Global symbol registration / sentinel leakage
NPS-96FDC8169933
Uses Symbol.for("zod.compile.invalid") and Symbol.for("zod.compile.fallback") in the global symbol registry. Benign in itself, but registers globally reachable sentinels that other code could in principle collide with.
dynamic code execution probe
NPS-04ACF78EC0BB
The allowsEval cached function probes for dynamic code execution capability via new Function(""), but this is a feature-detection pattern (checking if CSP/jitless environments permit eval), not an execution of external or untrusted input. The result is discarded and the construction is wrapped in try/catch. This is a common pattern in libraries that want to conditionally optimize code paths based on environment capabilities.
Dynamic code execution
NPS-90C99EB88B62
The code uses an IIFE that calls Object.getOwnPropertyDescriptor and Object.defineProperty to freeze exports; however this is a common pattern for module sealing, not obfuscated malicious code execution.
Top-level code execution / export sealing
NPS-5E10234CDD2B
The file contains an immediately-invoked function expression (IIFE) that runs at import time, iterating over all exported properties, invoking their getters, and redefining them as non-configurable frozen values before calling Object.freeze(exports). While this pattern is used by some libraries to enforce immutable CommonJS exports, it executes arbitrary getter logic at module load and permanently mutates the module exports object. This can interfere with consumers and is an unusual pattern that warrants review, though it does not appear to exfiltrate data or execute external code.
Dynamic getter invocation
NPS-15855FBA2433
The code calls desc.get() for every exported property whose descriptor defines a getter. If any re-exported module defines side-effecting getters, this would trigger those effects at import time. In this specific file the re-exported modules (errors, parseUtil, typeAliases, util, types, ZodError) are part of the Zod library and appear benign, but the mechanism itself is a potential vector for unexpected top-level execution.
Top-level code execution
NPS-B3A4073463C8
The file executes code at import time, including a prototype manipulation initializer and an IIFE that seals/freezes the module exports. This is standard module initialization behavior, not a malicious install-time hook.
Prototype mutation
NPS-B2717DA2D22D
The initializer lazily installs non-enumerable getter/setter methods on the prototype of ZodError instances. It explicitly guards against touching Object.prototype and Error.prototype via a WeakSet to avoid prototype pollution. This is a deliberate design choice, not an attack pattern.
sealed exports pattern
NPS-C202812A8C37
The 'seal-cjs-exports' IIFE at the bottom freezes the exports object and converts getter properties into non-writable, non-configurable values. This is a defensive measure used by some bundlers (e.g. esbuild-style or tsup output for Zod) to ensure CommonJS interop consistency. It does not execute external code, access the filesystem, or perform network activity. Behavior is deterministic and limited to the module's own exports object.
export sealing/freezing
NPS-D4E3D108B5BB
The file freezes its exports and replaces getters with static values to prevent later tampering. This is a legitimate hardening pattern used by Zod, not a malicious behavior.
Global prototype / object manipulation
NPS-E6010F034E57
Object.defineProperty on 'default', __createBinding, __setModuleDefault helpers mutate module exports. Standard TS/CommonJS interop, but the pattern combined with dynamic getter invocation in the sealing IIFE could be leveraged to force-evaluate attacker-injected getters if the package is compromised at publish time.
Dynamic RegExp construction from user-controlled strings
NPS-1150A5B87913
RegExp objects are dynamically constructed from def.includes, def.prefix, def.suffix in $ZodCheckIncludes, $ZodCheckStartsWith, $ZodCheckEndsWith. Values are passed through util.escapeRegex first, which mitigates ReDoS injection, but the pattern still takes runtime input into RegExp construction. This is legitimate validation logic for zod, not malicious.
Top-level execution at import time
NPS-F5A84ED7C8DE
The file executes an IIFE ('seal-cjs-exports') at module load time that enumerates all exports, invokes their getters, and freezes the exports object. Getters can run arbitrary code; while here they resolve to defined constructors, this pattern (firing property getters on import and freezing the module namespace) is unusual for a plain library module and can force evaluation of lazily-initialized code paths at import.
Expected validation logic
NPS-EDD5E444102F
The file implements Zod validation checks (min/max length, size, numeric bounds, regex/format checks, property validation, etc.) using constructor helpers. It imports only internal modules (core, regexes, util). No network, filesystem, process, environment, or dynamic code execution APIs are used. The eval-like comment in $ZodCheckProperty is a legitimate regex anchor comment, not dynamic code execution. No obfuscated payloads, credential harvesting, exfiltration, mining, or backdoor patterns are present.
Patching of parse/safeParse/run methods
NPS-CA889278A0E7
installCompiledUserMethods replaces parse and safeParse on the returned schema clone, and withParser replaces _zod.run. This is documented compiler behavior for schema objects only, not globals, and it captures originalRun/originalParse fallbacks. It is not a global monkey-patch, but it does mutate exported API surface and should be confirmed to not affect unrelated objects.
Getters invoked during generated validation
NPS-0B6AB5B1D13C
Generated code reads input properties once and calls .trim(), .toLowerCase(), .includes(), instanceof, %, etc. Object getters on untrusted input are invoked during fast-path validation (cached once per key, but still executed). This matches runtime parser behavior, though it means the compiled fast path is not safe for hostile objects with side-effecting getters unless the runtime parser has the same property.
Prototype manipulation handling
NPS-0B4E6D6A6E72
The code explicitly guards against __proto__ keys in object shapes, records, and catchall loops (obj["__proto__"] prototype setter concerns). These guards appear defensive and correctness-oriented, but repeated handling of __proto__ and Object.getOwnPropertyNames/getOwnPropertySymbols walks indicates the compiler accepts attacker-influenced key names and must be audited to ensure the guards cannot be bypassed to cause prototype pollution in generated outputs.
Invocation of user-supplied callbacks in generated code
NPS-7D1185359180
Multiple generated sections call user callbacks directly: refinements (def.fn), superRefine checks (check._zod.check), transforms, overwrite transforms, catch values, lazy getters, string-format predicates, and discriminated-union literals. These are expected schema-author-owned functions, but they are hoisted into generated source and invoked at parse time. The helpers generateTransformCheck, generatePipeCheck, and generateCustomRefineCheck spoof payload/addIssue and deliberately do not catch throws, allowing arbitrary exceptions from user code to propagate.
No data exfiltration, network, filesystem, or process-spawning patterns detected
NPS-56C1570810EB
The file does not import or reference any network APIs, environment variables, credential files, child_process, shell commands, filesystem manipulation, or crypto wallet logic. No obfuscation or encoded payloads were found.
Modification of global Error.stackTraceLimit
NPS-3C599C8FB2EA
newError temporarily sets Error.stackTraceLimit = 0 and restores it. It handles failures, but it still mutates a shared global object at parse time. If the restore is interrupted (e.g., a getter/setter trap on Error, or concurrent async code), the global stack trace limit can be left in an altered state for the entire process. This is a global side-effect rather than a security compromise, but it is a cross-cutting mutation of a shared builtin.
Top-level global side effect on import
NPS-3D199E5D0B68
At module import time the code runs (_a = globalThis).__zod_globalConfig ?? (_a.__zod_globalConfig = {}), unconditionally creating a global property on the host environment. Importing the package therefore mutates the global object, which is a side effect that can interact with other libraries or be used as a coordination channel by other packages.
dynamic-code-execution
NPS-4CC687A273FA
The code wraps schema parse functions at runtime and manipulates prototype-like properties, but does not use eval, Function constructor, or any dynamic code execution from external input. The wrapping is internal to the Zod memoization logic.
install-time-execution
NPS-AF65CB852766
The file contains an IIFE at the bottom that seals and freezes exports at import time. This executes on module load but performs only local property descriptor inspection and freezing of its own exports; no network, filesystem, or process access.
global state pollution
NPS-BC3C88AD5DE4
The code assigns a global registry to globalThis.__zod_globalRegistry. This is expected Zod behavior for sharing a registry across module instances, not a malicious pattern. It only stores schema references and metadata locally and performs no network, filesystem, or process operations.
Import-time module sealing
NPS-F26A4FC95641
A top-level IIFE at the end of the file ('seal-cjs-exports') converts getter-only export properties into frozen data properties and calls Object.freeze(exports). This runs at import time but is a benign anti-tampering measure on the module's own exports; it does not touch global state, files, network, or processes.
Dynamic code execution probe
NPS-9B329B5A88BB
The allowsEval cached getter uses new Function("") to probe whether eval-like dynamic code execution is allowed. While wrapped in try/catch and gated by config/userAgent checks, it directly invokes the Function constructor, which is a red-flag pattern for dynamic code execution and could be abused if the cached result or configuration is tampered with. The code does not actually execute attacker-controlled strings, but the presence of new Function at module import time is noteworthy.
Top-level execution on import
NPS-41C16C7CD885
The file contains a top-level IIFE 'seal-cjs-exports' that runs at import time, iterating over exports, invoking getters, and freezing the exports object. This is benign module hardening but constitutes code that executes on import. No network, filesystem, or process access is involved.
Insecure randomness generation
NPS-5519D147D384
randomString uses Math.random() to generate strings. This is unsuitable for any security-sensitive use (tokens, IDs, nonces). The function is exported and could be misused by downstream callers expecting cryptographic randomness. This is a security-hygiene issue, not a malicious pattern.
Prototype pollution surface
NPS-385520BA3E80
Several utilities manipulate object descriptors and prototypes (mergeDefs, createTransparentProxy, putProp, mirrorShape, defineLazy, defineLazyInternal, installLazyProp, members, derived). finalizeIssue explicitly skips __proto__ keys, indicating awareness of prototype pollution. The code generally guards against inherited setters with assignProp/own, but the extensive use of Reflect and Object.defineProperty on arbitrary keys is a potential attack surface if inputs are attacker-controlled.
prototype-sensitive property writes
NPS-A82024CEA093
Helpers such as putProp, assignProp, deferProp, defineLazy, and defineLazyInternal use Object.defineProperty and guard with key in target. The code includes explicit defenses against __proto__ setter abuse and prototype pollution in putProp and finalizeIssue, indicating awareness of these risks rather than exploitation.
weak randomness
NPS-473085D25553
randomString uses Math.random(), which is not cryptographically secure. This is a quality concern for security-sensitive use but not malicious; it appears intended for non-cryptographic identifiers.
dynamic code execution probe
NPS-BE2AC035AEB6
The allowsEval helper uses new Function('') to detect whether CSP/JIT restrictions allow dynamic code evaluation. This is a capability probe with the throw swallowed and no untrusted input passed, matching the documented purpose in the surrounding comment; it does not execute attacker-controlled code.
Sealed exports pattern
NPS-2933FF9824E9
The code freezes the exports object and converts getters to static values. This is a defensive pattern to prevent runtime modification and does not constitute malicious behavior.
Deprecated alias
NPS-7FBA43DB92FE
This file only re-exports the Ukrainian locale from './uk.cjs' and marks the previous 'ua' locale as deprecated. It contains no suspicious imports, network calls, environment access, dynamic execution, or process spawning.
Top-level code execution
NPS-B6527AE9C537
The IIFE at the end of the file runs at import time to seal/freeze the exports object. This is a benign pattern used to prevent mutation of exports and does not perform any malicious activity such as network access, file system manipulation, or process spawning.
Code that runs at import time
NPS-E6F1D042D337
An IIFE executes at module load to seal exports by converting getters to static values and freezing the exports object. This is a defensive measure to prevent export tampering, not malicious. It does not access external resources, environment variables, or execute dynamic code.
Import-time side effects / export sealing
NPS-610DEC9923C8
The IIFE at the end of the module executes at import time, iterating over all own property names of exports, invoking getters, and redefining them as non-configurable, non-writable frozen values before calling Object.freeze(exports). While this pattern is a defensive measure common in library bundles (here likely to fix circular-require semantics), it is a top-level side effect that mutates the module namespace and can break consumers relying on live bindings or monkey-patching. Any module that runs code on import deserves scrutiny, though no exfiltration or command execution is present.
Dynamic getter invocation from exports
NPS-CED5E7F482FF
The sealing IIFE calls desc.get() on every configurable getter export. If any export were defined as a getter with side effects, those side effects would be triggered at import time. In this file the getters map to plain schema functions, so no malicious behavior occurs, but the pattern of invoking accessors over the whole exports object is unusual and would be a useful camouflage for lazily triggered payloads in a tampered package.
Files reviewed
| File | Verdict | What the reviewer saw |
|---|---|---|
| v4/core/checks.cjs | critical | This is the legitimate zod v4 validation library's checks module; no exfiltration, credential harvesting, shell spawning, network calls, install-time hooks, or obfuscated payloads are present, though it uses dynamic getter evaluation and RegExp construction patterns that would be concerning if the package were tampered with. |
| v4/core/doc.cjs | critical | The Doc class dynamically compiles and executes arbitrary JavaScript via the Function constructor using content, argument names, and closed-over values, enabling code injection/RCE if any of these are influenced by untrusted input. |
| compile.cjs | medium | This is a legitimate zod compiler side-effect module that performs global monkey-patching and relies on a dynamic code compiler, but contains no exfiltration, credential harvesting, network access, process spawning, or other overtly malicious patterns. |
| src/compile.ts | medium | This module is not overtly malicious and contains no exfiltration, credential harvesting, shell execution, or network access, but it performs process-wide global monkey-patching and triggers dynamic JIT code generation at parse time via a side-effect import, which warrants caution. |
| src/v4/core/compile.ts | medium | This is a legitimate Zod AOT compiler module whose only notable security-relevant behavior is deliberate new Function code generation (with explicit source-injection guards) plus invocation of user-supplied schema callbacks; no exfiltration, credential harvesting, network, process, or filesystem activity was found. |
| src/v4/core/doc.ts | medium | The file implements a code-generation utility that uses new Function for dynamic evaluation; no exfiltration, credential harvesting, process spawning, or network activity was detected, but dynamic code execution warrants review of how Doc content is populated. |
| v3/external.cjs | medium | The file is a standard Zod CommonJS re-export shim with an additional export-sealing IIFE that mutates and freezes exports at import time; no exfiltration, credential harvesting, obfuscation, or dynamic code execution was found, but the runtime export mutation is worth noting. |
| v4/core/compile.cjs | medium | This is a legitimate Zod AOT compiler module that intentionally uses new Function to emit fast-path validators from schema definitions; the dynamic code generation and invocation of user callbacks are inherent to its purpose, but they represent the main security-relevant surface and require the existing escaping/type backstops to remain sound. |
| v4/core/compile.js | medium | This is a legitimate Zod schema compiler that relies on dynamic code generation via new Function; the main security concern is the inherent risk of codegen-based execution and string interpolation of schema values into generated source, though mitigation guards are present. |
| v4/core/core.js | medium | No direct malicious behavior (no exfiltration, eval, shells, or credential theft) was found, but the module exposes an undocumented global postProcessor hook invoked on every schema construction and mutates global Error/globalThis state at import and runtime, which warrants caution. |
| v4/core/doc.js | medium | The code contains dynamic code execution via the Function constructor, which is a potential security risk if untrusted input can reach the write method. |
| v4/core/util.cjs | medium | This is legitimate Zod v4 utility code (schema manipulation, lazy property installation, encoding helpers); it contains no exfiltration, credential harvesting, backdoors, or process/network abuse, though it uses new Function for a capability probe and Math.random() for string generation, both non-malicious but worth noting. |
| v4/mini/schemas.cjs | medium | This is the legitimate Zod Mini schema definition file; the only notable behavior is an import-time IIFE that freezes/seals exports, which is a defensive pattern rather than a malicious one, so the file is not a security risk but does contain non-trivial top-level side effects. |
| compile.js | safe | No malicious patterns detected; the file only installs an internal compile-time optimization shim with no network, filesystem, process, or obfuscation behavior. |
| index.cjs | safe | No malicious patterns detected |
| index.js | safe | Cleared by Jev triage; no further analysis needed |
| locales/index.cjs | safe | This is a standard TypeScript-generated CommonJS re-export file that seals exports; no malicious patterns detected. |
| locales/index.js | safe | Cleared by Jev triage; no further analysis needed |
| mini/index.cjs | safe | No malicious patterns detected; the file contains standard TypeScript/CommonJS interop helpers and a defensive export-sealing routine. |
| mini/index.js | safe | Cleared by Jev triage; no further analysis needed |
| src/index.ts | safe | Cleared by Jev triage; no further analysis needed |
| src/locales/index.ts | safe | Cleared by Jev triage; no further analysis needed |
| src/mini/index.ts | safe | Cleared by Jev triage; no further analysis needed |
| src/v3/ZodError.ts | safe | This is the legitimate Zod error-handling module; no malicious patterns, network calls, credential access, dynamic execution, or install-time behavior were detected. |
| src/v3/benchmarks/datetime.ts | safe | Cleared by Jev triage; no further analysis needed |
Show 350 more files
| File | Verdict | What the reviewer saw |
|---|---|---|
| src/v3/benchmarks/discriminatedUnion.ts | safe | Cleared by Jev triage; no further analysis needed |
| src/v3/benchmarks/index.ts | safe | No malicious patterns detected; the file is a standard benchmark runner that reads CLI arguments and runs in-memory benchmarks without network, filesystem, or process-spawning operations. |
| src/v3/benchmarks/ipv4.ts | safe | Cleared by Jev triage; no further analysis needed |
| src/v3/benchmarks/object.ts | safe | Cleared by Jev triage; no further analysis needed |
| src/v3/benchmarks/primitives.ts | safe | Cleared by Jev triage; no further analysis needed |
| src/v3/benchmarks/realworld.ts | safe | No malicious patterns detected; the code is a standard Zod validation benchmark with no network, filesystem, process, or obfuscated behavior. |
| src/v3/benchmarks/string.ts | safe | Cleared by Jev triage; no further analysis needed |
| src/v3/benchmarks/union.ts | safe | Cleared by Jev triage; no further analysis needed |
| src/v3/errors.ts | safe | Cleared by Jev triage; no further analysis needed |
| src/v3/external.ts | safe | Cleared by Jev triage; no further analysis needed |
| src/v3/helpers/enumUtil.ts | safe | Cleared by Jev triage; no further analysis needed |
| src/v3/helpers/errorUtil.ts | safe | Cleared by Jev triage; no further analysis needed |
| src/v3/helpers/parseUtil.ts | safe | Cleared by Jev triage; no further analysis needed |
| src/v3/helpers/partialUtil.ts | safe | Cleared by Jev triage; no further analysis needed |
| src/v3/helpers/typeAliases.ts | safe | Cleared by Jev triage; no further analysis needed |
| src/v3/helpers/util.ts | safe | Cleared by Jev triage; no further analysis needed |
| src/v3/index.ts | safe | Cleared by Jev triage; no further analysis needed |
| src/v3/locales/en.ts | safe | Cleared by Jev triage; no further analysis needed |
| src/v3/standard-schema.ts | safe | Cleared by Jev triage; no further analysis needed |
| src/v4-mini/index.ts | safe | Cleared by Jev triage; no further analysis needed |
| src/v4/classic/checks.ts | safe | Cleared by Jev triage; no further analysis needed |
| src/v4/classic/coerce.ts | safe | Cleared by Jev triage; no further analysis needed |
| src/v4/classic/compat.ts | safe | Cleared by Jev triage; no further analysis needed |
| src/v4/classic/deep-partial.ts | safe | Cleared by Jev triage; no further analysis needed |
| src/v4/classic/errors.ts | safe | No malicious patterns detected; the code only implements error handling and prototype-based lazy method installation for Zod validation errors. |
| src/v4/classic/external.ts | safe | Cleared by Jev triage; no further analysis needed |
| src/v4/classic/from-json-schema.ts | safe | The file is a legitimate JSON Schema to Zod converter with no network, filesystem, process-spawning, credential-harvesting, or dynamic-code-execution behavior; minor ReDoS considerations from user-supplied regex patterns are inherent to JSON Schema. |
| src/v4/classic/in-out.ts | safe | Cleared by Jev triage; no further analysis needed |
| src/v4/classic/index.ts | safe | Cleared by Jev triage; no further analysis needed |
| src/v4/classic/iso.ts | safe | Cleared by Jev triage; no further analysis needed |
| src/v4/classic/parse.ts | safe | Cleared by Jev triage; no further analysis needed |
| src/v4/core/api.ts | safe | Cleared by Jev triage; no further analysis needed |
| src/v4/core/checks.ts | safe | Cleared by Jev triage; no further analysis needed |
| src/v4/core/core.ts | safe | No malicious patterns detected; the code is part of Zod's core constructor logic with no data exfiltration, credential harvesting, dynamic code execution, or process spawning. |
| src/v4/core/errors.ts | safe | No malicious patterns detected; the file contains only type definitions and error-formatting utilities with explicit prototype-pollution hardening, no network, filesystem, process, or dynamic execution behavior. |
| src/v4/core/index.ts | safe | Cleared by Jev triage; no further analysis needed |
| src/v4/core/json-schema-generator.ts | safe | Cleared by Jev triage; no further analysis needed |
| src/v4/core/json-schema-processors.ts | safe | Cleared by Jev triage; no further analysis needed |
| src/v4/core/json-schema.ts | safe | Cleared by Jev triage; no further analysis needed |
| src/v4/core/memoizer.ts | safe | The TypeScript memoizer implements schema parsing cycle detection and caching with no network, filesystem, process, or dynamic code execution patterns. |
| src/v4/core/parse.ts | safe | Cleared by Jev triage; no further analysis needed |
| src/v4/core/regexes.ts | safe | No malicious patterns detected; the file only defines regexes and regex-builder helpers for validation purposes. |
| src/v4/core/registries.ts | safe | No malicious patterns detected; the code implements a Zod metadata registry with type utilities and a global registry singleton, with no exfiltration, credential harvesting, obfuscation, process spawning, or other red flags. |
| src/v4/core/standard-schema.ts | safe | Cleared by Jev triage; no further analysis needed |
| src/v4/core/to-json-schema.ts | safe | No malicious patterns detected; this is a legitimate Zod v4 JSON Schema conversion utility with no network, filesystem, process, or dynamic code execution activity. |
| src/v4/core/util.ts | safe | This is a utility/type-definitions module from a Zod-like validation library; no malicious patterns such as data exfiltration, credential harvesting, obfuscated payloads, backdoors, or process spawning were detected, with only a benign eval-capability feature-detection probe present. |
| src/v4/core/versions.ts | safe | Cleared by Jev triage; no further analysis needed |
| src/v4/core/visit.ts | safe | Cleared by Jev triage; no further analysis needed |
| src/v4/core/zsf.ts | safe | Cleared by Jev triage; no further analysis needed |
| src/v4/index.ts | safe | Cleared by Jev triage; no further analysis needed |
| src/v4/locales/ar.ts | safe | Cleared by Jev triage; no further analysis needed |
| src/v4/locales/az.ts | safe | Cleared by Jev triage; no further analysis needed |
| src/v4/locales/be.ts | safe | Cleared by Jev triage; no further analysis needed |
| src/v4/locales/bg.ts | safe | Cleared by Jev triage; no further analysis needed |
| src/v4/locales/bn.ts | safe | Cleared by Jev triage; no further analysis needed |
| src/v4/locales/ca.ts | safe | Cleared by Jev triage; no further analysis needed |
| src/v4/locales/ckb.ts | safe | Cleared by Jev triage; no further analysis needed |
| src/v4/locales/cs.ts | safe | Cleared by Jev triage; no further analysis needed |
| src/v4/locales/da.ts | safe | Cleared by Jev triage; no further analysis needed |
| src/v4/locales/de.ts | safe | Cleared by Jev triage; no further analysis needed |
| src/v4/locales/el.ts | safe | Cleared by Jev triage; no further analysis needed |
| src/v4/locales/en.ts | safe | Cleared by Jev triage; no further analysis needed |
| src/v4/locales/eo.ts | safe | Cleared by Jev triage; no further analysis needed |
| src/v4/locales/es.ts | safe | Cleared by Jev triage; no further analysis needed |
| src/v4/locales/fa.ts | safe | Cleared by Jev triage; no further analysis needed |
| src/v4/locales/fi.ts | safe | Cleared by Jev triage; no further analysis needed |
| src/v4/locales/fr-CA.ts | safe | Cleared by Jev triage; no further analysis needed |
| src/v4/locales/fr.ts | safe | Cleared by Jev triage; no further analysis needed |
| src/v4/locales/gu.ts | safe | Cleared by Jev triage; no further analysis needed |
| src/v4/locales/he.ts | safe | Cleared by Jev triage; no further analysis needed |
| src/v4/locales/hi.ts | safe | Cleared by Jev triage; no further analysis needed |
| src/v4/locales/hr.ts | safe | Cleared by Jev triage; no further analysis needed |
| src/v4/locales/hu.ts | safe | Cleared by Jev triage; no further analysis needed |
| src/v4/locales/hy.ts | safe | Cleared by Jev triage; no further analysis needed |
| src/v4/locales/id.ts | safe | Cleared by Jev triage; no further analysis needed |
| src/v4/locales/index.ts | safe | Cleared by Jev triage; no further analysis needed |
| src/v4/locales/is.ts | safe | Cleared by Jev triage; no further analysis needed |
| src/v4/locales/it.ts | safe | Cleared by Jev triage; no further analysis needed |
| src/v4/locales/ja.ts | safe | Cleared by Jev triage; no further analysis needed |
| src/v4/locales/ka.ts | safe | Cleared by Jev triage; no further analysis needed |
| src/v4/locales/kh.ts | safe | Cleared by Jev triage; no further analysis needed |
| src/v4/locales/km.ts | safe | Cleared by Jev triage; no further analysis needed |
| src/v4/locales/kn.ts | safe | Cleared by Jev triage; no further analysis needed |
| src/v4/locales/ko.ts | safe | Cleared by Jev triage; no further analysis needed |
| src/v4/locales/lt.ts | safe | Cleared by Jev triage; no further analysis needed |
| src/v4/locales/mk.ts | safe | Cleared by Jev triage; no further analysis needed |
| src/v4/locales/ms.ts | safe | Cleared by Jev triage; no further analysis needed |
| src/v4/locales/ne.ts | safe | Cleared by Jev triage; no further analysis needed |
| src/v4/locales/nl.ts | safe | Cleared by Jev triage; no further analysis needed |
| src/v4/locales/nn.ts | safe | Cleared by Jev triage; no further analysis needed |
| src/v4/locales/no.ts | safe | Cleared by Jev triage; no further analysis needed |
| src/v4/locales/ota.ts | safe | Cleared by Jev triage; no further analysis needed |
| src/v4/locales/pl.ts | safe | Cleared by Jev triage; no further analysis needed |
| src/v4/locales/ps.ts | safe | Cleared by Jev triage; no further analysis needed |
| src/v4/locales/pt-BR.ts | safe | Cleared by Jev triage; no further analysis needed |
| src/v4/locales/pt.ts | safe | Cleared by Jev triage; no further analysis needed |
| src/v4/locales/ro.ts | safe | Cleared by Jev triage; no further analysis needed |
| src/v4/locales/ru.ts | safe | Cleared by Jev triage; no further analysis needed |
| src/v4/locales/sk.ts | safe | Cleared by Jev triage; no further analysis needed |
| src/v4/locales/sl.ts | safe | Cleared by Jev triage; no further analysis needed |
| src/v4/locales/sv.ts | safe | Cleared by Jev triage; no further analysis needed |
| src/v4/locales/ta.ts | safe | Cleared by Jev triage; no further analysis needed |
| src/v4/locales/tg.ts | safe | Cleared by Jev triage; no further analysis needed |
| src/v4/locales/th.ts | safe | Cleared by Jev triage; no further analysis needed |
| src/v4/locales/tk.ts | safe | Cleared by Jev triage; no further analysis needed |
| src/v4/locales/tr.ts | safe | Cleared by Jev triage; no further analysis needed |
| src/v4/locales/ua.ts | safe | Cleared by Jev triage; no further analysis needed |
| src/v4/locales/uk.ts | safe | Cleared by Jev triage; no further analysis needed |
| src/v4/locales/ur.ts | safe | Cleared by Jev triage; no further analysis needed |
| src/v4/locales/uz.ts | safe | Cleared by Jev triage; no further analysis needed |
| src/v4/locales/vi.ts | safe | Cleared by Jev triage; no further analysis needed |
| src/v4/locales/yo.ts | safe | Cleared by Jev triage; no further analysis needed |
| src/v4/locales/zh-CN.ts | safe | Cleared by Jev triage; no further analysis needed |
| src/v4/locales/zh-TW.ts | safe | Cleared by Jev triage; no further analysis needed |
| src/v4/mini/checks.ts | safe | Cleared by Jev triage; no further analysis needed |
| src/v4/mini/coerce.ts | safe | Cleared by Jev triage; no further analysis needed |
| src/v4/mini/deep-partial.ts | safe | Cleared by Jev triage; no further analysis needed |
| src/v4/mini/external.ts | safe | Cleared by Jev triage; no further analysis needed |
| src/v4/mini/in-out.ts | safe | Cleared by Jev triage; no further analysis needed |
| src/v4/mini/index.ts | safe | Cleared by Jev triage; no further analysis needed |
| src/v4/mini/iso.ts | safe | Cleared by Jev triage; no further analysis needed |
| src/v4/mini/parse.ts | safe | Cleared by Jev triage; no further analysis needed |
| src/v4/mini/schemas.ts | safe | Cleared by Jev triage; no further analysis needed |
| v3/ZodError.cjs | safe | No malicious patterns detected; this is standard Zod error-handling code with prototype-safe error formatting and export sealing. |
| v3/ZodError.js | safe | No malicious patterns detected; the code is a standard Zod error-handling implementation with no exfiltration, obfuscation, dynamic execution, or filesystem/network abuse. |
| v3/errors.cjs | safe | No malicious patterns detected; the code only manages error map overrides and seals exports using standard reflection APIs. |
| v3/errors.js | safe | Cleared by Jev triage; no further analysis needed |
| v3/external.js | safe | Cleared by Jev triage; no further analysis needed |
| v3/helpers/enumUtil.cjs | safe | The code only seals and freezes the module's exports object; no malicious patterns detected. |
| v3/helpers/enumUtil.js | safe | Cleared by Jev triage; no further analysis needed |
| v3/helpers/errorUtil.cjs | safe | No malicious patterns detected; the file only provides simple error message conversion utilities and a defensive export sealing routine that executes at import time but performs no external, filesystem, or process operations. |
| v3/helpers/errorUtil.js | safe | No malicious patterns detected |
| v3/helpers/parseUtil.cjs | safe | No malicious patterns detected; the file contains only standard Zod library parsing utilities with no network, filesystem, credential, or code-execution activity. |
| v3/helpers/parseUtil.js | safe | Cleared by Jev triage; no further analysis needed |
| v3/helpers/partialUtil.cjs | safe | The code only seals and freezes the module's exports object; no malicious patterns detected. |
| v3/helpers/partialUtil.js | safe | Cleared by Jev triage; no further analysis needed |
| v3/helpers/typeAliases.cjs | safe | The code only seals and freezes the module's exports object; no malicious patterns detected. |
| v3/helpers/typeAliases.js | safe | Cleared by Jev triage; no further analysis needed |
| v3/helpers/util.cjs | safe | No malicious patterns detected; the code is a standard Zod utility module with a benign export-sealing routine. |
| v3/helpers/util.js | safe | No malicious patterns detected |
| v3/index.cjs | safe | No malicious patterns detected; the code is a standard CommonJS export shim with a sealing mechanism that freezes exports, containing no data exfiltration, credential harvesting, obfuscation, or dynamic code execution. |
| v3/index.js | safe | Cleared by Jev triage; no further analysis needed |
| v3/locales/en.cjs | safe | Cleared by Jev triage; no further analysis needed |
| v3/locales/en.js | safe | Cleared by Jev triage; no further analysis needed |
| v3/standard-schema.cjs | safe | The code only seals and freezes the module's exports object; no malicious patterns detected. |
| v3/standard-schema.js | safe | Cleared by Jev triage; no further analysis needed |
| v4-mini/index.cjs | safe | No malicious patterns detected; the file contains standard TypeScript/CommonJS interop helpers and a defensive export-sealing routine. |
| v4-mini/index.js | safe | Cleared by Jev triage; no further analysis needed |
| v4/classic/checks.cjs | safe | The file is a standard re-export module that delegates validation checks to ../core/index.cjs and freezes exports; no malicious patterns, obfuscation, network, filesystem, or process activity detected. |
| v4/classic/checks.js | safe | Cleared by Jev triage; no further analysis needed |
| v4/classic/coerce.cjs | safe | No malicious patterns detected; the file contains standard TypeScript/CommonJS helper functions and Zod schema wrappers with no network, filesystem, process, or obfuscation concerns. |
| v4/classic/coerce.js | safe | Cleared by Jev triage; no further analysis needed |
| v4/classic/compat.cjs | safe | No malicious patterns detected; the file is a standard TypeScript-generated Zod v3 compatibility shim that only re-exports core utilities and freezes its exports. |
| v4/classic/compat.js | safe | Cleared by Jev triage; no further analysis needed |
| v4/classic/deep-partial.cjs | safe | No malicious patterns detected; the code is standard TypeScript/CommonJS interop and Zod schema transformation logic with an export-sealing helper. |
| v4/classic/deep-partial.js | safe | Cleared by Jev triage; no further analysis needed |
| v4/classic/errors.cjs | safe | The file is a standard CommonJS build artifact for Zod error classes; it contains only module initialization, lazy prototype helpers, and export sealing, with no exfiltration, credential harvesting, dynamic code execution, or shell/process spawning. |
| v4/classic/errors.js | safe | No malicious patterns detected; the code implements lazy error-method installation for ZodError with no network, filesystem, process, or dynamic-execution behavior. |
| v4/classic/external.cjs | safe | This is a standard TypeScript-compiled CommonJS re-export barrel file for the zod library with no malicious patterns detected. |
| v4/classic/external.js | safe | Cleared by Jev triage; no further analysis needed |
| v4/classic/from-json-schema.cjs | safe | No malicious patterns detected; the file is a legitimate JSON Schema to Zod converter with no network, filesystem, process, or dynamic execution risks. |
| v4/classic/from-json-schema.js | safe | No malicious patterns detected; the code is a legitimate JSON Schema to Zod converter with no network, filesystem, process, or dynamic execution activities. |
| v4/classic/in-out.cjs | safe | This is a standard Zod library utility module that performs schema traversal and cloning with no malicious patterns detected. |
| v4/classic/in-out.js | safe | Cleared by Jev triage; no further analysis needed |
| v4/classic/index.cjs | safe | No malicious patterns detected; the code is standard TypeScript-generated CJS interop boilerplate with a safe export-sealing IIFE. |
| v4/classic/index.js | safe | Cleared by Jev triage; no further analysis needed |
| v4/classic/iso.cjs | safe | This is a standard CommonJS interop wrapper for the Zod ISO schema module with a benign export-sealing IIFE; no malicious patterns were detected. |
| v4/classic/iso.js | safe | Cleared by Jev triage; no further analysis needed |
| v4/classic/parse.cjs | safe | No malicious patterns detected; the code is standard Zod CJS export wiring with export sealing. |
| v4/classic/parse.js | safe | Cleared by Jev triage; no further analysis needed |
| v4/classic/schemas.cjs | safe | This is a legitimate Zod schema validation library file with no malicious patterns detected; the top-level code only sets up the module exports and freezes them. |
| v4/classic/schemas.js | safe | The file is a standard Zod v4 schema definition module containing only type/validation logic, with no data exfiltration, credential harvesting, obfuscation, network calls, process spawning, or other malicious patterns. |
| v4/core/api.cjs | safe | No malicious patterns detected |
| v4/core/api.js | safe | Cleared by Jev triage; no further analysis needed |
| v4/core/checks.js | safe | This is legitimate zod validation-check implementation code with no malicious patterns detected. |
| v4/core/core.cjs | safe | The code is a legitimate Zod v4 core module implementing schema construction internals, with no evidence of exfiltration, credential harvesting, obfuscation, dynamic code execution, process spawning, network activity, or install-time hook abuse. |
| v4/core/errors.cjs | safe | No malicious patterns detected; the code is a standard Zod error formatting module with defensive prototype-pollution guards and export freezing, and performs no network, filesystem, process, or dynamic code execution activity. |
| v4/core/errors.js | safe | The code is part of the Zod validation library and contains no malicious patterns; the defensive prototype-pollution handling is legitimate security hardening. |
| v4/core/index.cjs | safe | This file is a standard TypeScript-compiled CommonJS barrel export with a sealing/freeze routine that remaps getters to concrete values and locks exports; no malicious patterns detected. |
| v4/core/index.js | safe | Cleared by Jev triage; no further analysis needed |
| v4/core/json-schema-generator.cjs | safe | The file is a legitimate JSON Schema generator wrapper with no malicious patterns such as data exfiltration, credential harvesting, dynamic code execution, or network activity. |
| v4/core/json-schema-generator.js | safe | Cleared by Jev triage; no further analysis needed |
| v4/core/json-schema-processors.cjs | safe | No malicious patterns detected; the file is a standard Zod JSON Schema generator with TypeScript helper boilerplate and an export-sealing IIFE, with no network, filesystem, or process activity. |
| v4/core/json-schema-processors.js | safe | Cleared by Jev triage; no further analysis needed |
| v4/core/json-schema.cjs | safe | The code only seals and freezes the module's exports object; no malicious patterns detected. |
| v4/core/json-schema.js | safe | Cleared by Jev triage; no further analysis needed |
| v4/core/memoizer.cjs | safe | The code is a legitimate Zod library memoizer implementing cycle detection and caching; no malicious patterns such as exfiltration, credential harvesting, obfuscation, backdoors, or network/process activity were detected. |
| v4/core/memoizer.js | safe | No malicious patterns detected; the code is a legitimate cycle-detection and memoization utility for Zod schema parsing with no network, filesystem, process, or dynamic execution behavior. |
| v4/core/parse.cjs | safe | No malicious patterns detected; the file contains standard Zod schema parsing/encoding logic with no exfiltration, credential harvesting, obfuscation, process spawning, or dynamic code execution. |
| v4/core/parse.js | safe | Cleared by Jev triage; no further analysis needed |
| v4/core/regexes.cjs | safe | No malicious patterns detected; the file only defines validation regular expressions and helper functions with no network, filesystem, process, credential, or dynamic code execution behavior. |
| v4/core/regexes.js | safe | No malicious patterns detected; the file contains only regular expression definitions for validation with no network, filesystem, process, or dynamic code execution activity. |
| v4/core/registries.cjs | safe | No malicious patterns detected; the code implements a standard Zod schema registry with global registration and export sealing, containing no network, filesystem, process, or dynamic execution activity. |
| v4/core/registries.js | safe | No malicious patterns detected; the code only implements an in-memory schema metadata registry using WeakMap/Map and a shared global registry symbol. |
| v4/core/standard-schema.cjs | safe | The code only seals and freezes the module's exports object; no malicious patterns detected. |
| v4/core/standard-schema.js | safe | Cleared by Jev triage; no further analysis needed |
| v4/core/to-json-schema.cjs | safe | No malicious patterns detected; the file is a JSON Schema conversion module for Zod with only a benign import-time export-sealing IIFE. |
| v4/core/to-json-schema.js | safe | This is a legitimate Zod JSON Schema converter with no malicious patterns, network calls, credential access, dynamic code execution, or install-time side effects. |
| v4/core/util.js | safe | This is a utility module (appearing to be zod v4 internals) containing no data exfiltration, credential harvesting, shell/process execution, obfuscation, backdoors, or install-time side effects; the only notable items are a benign new Function('') capability probe and non-cryptographic Math.random() usage. |
| v4/core/versions.cjs | safe | No malicious patterns detected |
| v4/core/versions.js | safe | Cleared by Jev triage; no further analysis needed |
| v4/core/visit.cjs | safe | No malicious patterns detected; the file is a legitimate Zod schema traversal utility with no network, filesystem, process, or dynamic code execution activity. |
| v4/core/visit.js | safe | Cleared by Jev triage; no further analysis needed |
| v4/index.cjs | safe | The file contains only standard TypeScript/CommonJS interop helpers and an export-sealing utility with no malicious patterns detected. |
| v4/index.js | safe | Cleared by Jev triage; no further analysis needed |
| v4/locales/ar.cjs | safe | No malicious patterns detected; the file is a standard localized error message module for the Zod validation library with no network, filesystem, process, or dynamic execution behavior. |
| v4/locales/ar.js | safe | Cleared by Jev triage; no further analysis needed |
| v4/locales/az.cjs | safe | This is a standard localization/error message file for the Zod validation library, containing no malicious patterns, network calls, credential access, or dynamic code execution. |
| v4/locales/az.js | safe | Cleared by Jev triage; no further analysis needed |
| v4/locales/be.cjs | safe | No malicious patterns detected; the file is a standard localization module with only static translation strings and no network, filesystem, or code execution activity. |
| v4/locales/be.js | safe | Cleared by Jev triage; no further analysis needed |
| v4/locales/bg.cjs | safe | No malicious patterns detected; this is a standard Zod Bulgarian locale file with only localization strings and helper imports. |
| v4/locales/bg.js | safe | Cleared by Jev triage; no further analysis needed |
| v4/locales/bn.cjs | safe | No malicious patterns detected; this is a standard Zod localization file for Bengali containing only error message translations and safe module interop helpers. |
| v4/locales/bn.js | safe | Cleared by Jev triage; no further analysis needed |
| v4/locales/ca.cjs | safe | No malicious patterns detected |
| v4/locales/ca.js | safe | Cleared by Jev triage; no further analysis needed |
| v4/locales/ckb.cjs | safe | The file is a standard localization/translation module for Zod validation errors in Central Kurdish; it contains only static string dictionaries and error-formatting logic with no network, filesystem, process, or dynamic code execution patterns. |
| v4/locales/ckb.js | safe | Cleared by Jev triage; no further analysis needed |
| v4/locales/cs.cjs | safe | No malicious patterns detected; the file contains standard TypeScript/CommonJS module interop helpers and Czech localization strings for a validation library. |
| v4/locales/cs.js | safe | Cleared by Jev triage; no further analysis needed |
| v4/locales/da.cjs | safe | No malicious patterns detected; the code is a standard localization file for the Zod validation library. |
| v4/locales/da.js | safe | Cleared by Jev triage; no further analysis needed |
| v4/locales/de.cjs | safe | This is a standard localization/error message file for the Zod validation library with no malicious patterns detected. |
| v4/locales/de.js | safe | Cleared by Jev triage; no further analysis needed |
| v4/locales/el.cjs | safe | No malicious patterns detected; the file contains only Greek locale error message definitions for a validation library. |
| v4/locales/el.js | safe | Cleared by Jev triage; no further analysis needed |
| v4/locales/en.cjs | safe | No malicious patterns detected; the file is a standard TypeScript-compiled locale error message module with no network, filesystem, process execution, or dynamic code evaluation. |
| v4/locales/en.js | safe | Cleared by Jev triage; no further analysis needed |
| v4/locales/eo.cjs | safe | No malicious patterns detected |
| v4/locales/eo.js | safe | Cleared by Jev triage; no further analysis needed |
| v4/locales/es.cjs | safe | No malicious patterns detected |
| v4/locales/es.js | safe | Cleared by Jev triage; no further analysis needed |
| v4/locales/fa.cjs | safe | This is a localization file providing Persian (Farsi) error messages for the Zod validation library, with no malicious patterns detected. |
| v4/locales/fa.js | safe | Cleared by Jev triage; no further analysis needed |
| v4/locales/fi.cjs | safe | No malicious patterns detected |
| v4/locales/fi.js | safe | Cleared by Jev triage; no further analysis needed |
| v4/locales/fr-CA.cjs | safe | No malicious patterns detected |
| v4/locales/fr-CA.js | safe | Cleared by Jev triage; no further analysis needed |
| v4/locales/fr.cjs | safe | No malicious patterns detected; the file contains only standard localization/error message definitions for a validation library. |
| v4/locales/fr.js | safe | Cleared by Jev triage; no further analysis needed |
| v4/locales/gu.cjs | safe | No malicious patterns detected; the file is a standard locale translation module with only static error message strings and no network, filesystem, process, or dynamic code execution activity. |
| v4/locales/gu.js | safe | Cleared by Jev triage; no further analysis needed |
| v4/locales/he.cjs | safe | No malicious patterns detected; this is a standard Zod locale/error-message module for Hebrew with only static translations and no network, filesystem, process, or dynamic-execution behavior. |
| v4/locales/he.js | safe | Cleared by Jev triage; no further analysis needed |
| v4/locales/hi.cjs | safe | No malicious patterns detected |
| v4/locales/hi.js | safe | Cleared by Jev triage; no further analysis needed |
| v4/locales/hr.cjs | safe | No malicious patterns detected |
| v4/locales/hr.js | safe | Cleared by Jev triage; no further analysis needed |
| v4/locales/hu.cjs | safe | No malicious patterns detected |
| v4/locales/hu.js | safe | Cleared by Jev triage; no further analysis needed |
| v4/locales/hy.cjs | safe | No malicious patterns detected; the file is a straightforward localization module for Armenian error messages with no network, filesystem, process execution, or obfuscated code. |
| v4/locales/hy.js | safe | Cleared by Jev triage; no further analysis needed |
| v4/locales/id.cjs | safe | This is a standard Zod locale/error message file with no malicious patterns detected. |
| v4/locales/id.js | safe | Cleared by Jev triage; no further analysis needed |
| v4/locales/index.cjs | safe | No malicious patterns detected |
| v4/locales/index.js | safe | Cleared by Jev triage; no further analysis needed |
| v4/locales/is.cjs | safe | No malicious patterns detected; this is a standard Zod Icelandic locale error message module with no network, filesystem, process, eval, or credential-harvesting behavior. |
| v4/locales/is.js | safe | Cleared by Jev triage; no further analysis needed |
| v4/locales/it.cjs | safe | This is a standard Zod locale file for Italian error messages with no malicious patterns, network calls, or dynamic code execution beyond TypeScript's own import helpers. |
| v4/locales/it.js | safe | Cleared by Jev triage; no further analysis needed |
| v4/locales/ja.cjs | safe | No malicious patterns detected; this is a standard localization file for the Zod validation library containing Japanese error messages. |
| v4/locales/ja.js | safe | Cleared by Jev triage; no further analysis needed |
| v4/locales/ka.cjs | safe | No malicious patterns detected; this is a standard Zod locale file with only localization strings and helper functions. |
| v4/locales/ka.js | safe | Cleared by Jev triage; no further analysis needed |
| v4/locales/kh.cjs | safe | No malicious patterns detected; this is a simple deprecated locale alias that re-exports the 'km' locale with no external calls or dynamic execution. |
| v4/locales/kh.js | safe | Cleared by Jev triage; no further analysis needed |
| v4/locales/km.cjs | safe | No malicious patterns detected |
| v4/locales/km.js | safe | Cleared by Jev triage; no further analysis needed |
| v4/locales/kn.cjs | safe | No malicious patterns detected; the file is a standard localization module for validation error messages with only benign imports and pure message-formatting logic. |
| v4/locales/kn.js | safe | Cleared by Jev triage; no further analysis needed |
| v4/locales/ko.cjs | safe | This is a legitimate Korean locale file for the Zod validation library containing only translation strings and error message formatting logic with no malicious patterns. |
| v4/locales/ko.js | safe | Cleared by Jev triage; no further analysis needed |
| v4/locales/lt.cjs | safe | This is a legitimate Lithuanian locale/translation file for a validation library with no malicious patterns detected. |
| v4/locales/lt.js | safe | Cleared by Jev triage; no further analysis needed |
| v4/locales/mk.cjs | safe | This is a benign localization file for the Zod validation library containing only static Macedonian error message strings, with no malicious patterns detected. |
| v4/locales/mk.js | safe | Cleared by Jev triage; no further analysis needed |
| v4/locales/ms.cjs | safe | This file is a standard localization module for the Zod validation library containing only static error message translations and no malicious patterns. |
| v4/locales/ms.js | safe | Cleared by Jev triage; no further analysis needed |
| v4/locales/ne.cjs | safe | This is a localization module for the Zod validation library containing only static error message strings in Nepali; no malicious patterns, network activity, credential access, dynamic execution, or suspicious processes were detected. |
| v4/locales/ne.js | safe | Cleared by Jev triage; no further analysis needed |
| v4/locales/nl.cjs | safe | No malicious patterns detected |
| v4/locales/nl.js | safe | Cleared by Jev triage; no further analysis needed |
| v4/locales/nn.cjs | safe | No malicious patterns detected |
| v4/locales/nn.js | safe | Cleared by Jev triage; no further analysis needed |
| v4/locales/no.cjs | safe | No malicious patterns detected; this is a legitimate localization file for the Zod validation library containing Norwegian error messages. |
| v4/locales/no.js | safe | Cleared by Jev triage; no further analysis needed |
| v4/locales/ota.cjs | safe | No malicious patterns detected |
| v4/locales/ota.js | safe | Cleared by Jev triage; no further analysis needed |
| v4/locales/pl.cjs | safe | This is a standard localization file for the Zod validation library containing only Polish error message translations with no malicious patterns. |
| v4/locales/pl.js | safe | Cleared by Jev triage; no further analysis needed |
| v4/locales/ps.cjs | safe | This is a Zod Pashto locale file containing only error message translations and TypeScript helper boilerplate, with no malicious patterns detected. |
| v4/locales/ps.js | safe | Cleared by Jev triage; no further analysis needed |
| v4/locales/pt-BR.cjs | safe | No malicious patterns detected; this is a standard localization file for error messages with only TypeScript helper boilerplate and string translations. |
| v4/locales/pt-BR.js | safe | Cleared by Jev triage; no further analysis needed |
| v4/locales/pt.cjs | safe | The file is a Portuguese locale definition for the Zod validation library containing only static translation strings and error formatting logic, with no network, filesystem, process, or dynamic code execution activity. |
| v4/locales/pt.js | safe | Cleared by Jev triage; no further analysis needed |
| v4/locales/ro.cjs | safe | This file is a Zod library Romanian locale definition containing only translation strings and error message formatting logic; no malicious patterns detected. |
| v4/locales/ro.js | safe | Cleared by Jev triage; no further analysis needed |
| v4/locales/ru.cjs | safe | This is a standard Zod locale file containing only Russian translation strings and pluralization logic with no malicious patterns. |
| v4/locales/ru.js | safe | Cleared by Jev triage; no further analysis needed |
| v4/locales/sk.cjs | safe | No malicious patterns detected; file is a standard localization module for the Zod validation library with only static Slovak error messages and no dynamic execution, network, filesystem, or process activity. |
| v4/locales/sk.js | safe | Cleared by Jev triage; no further analysis needed |
| v4/locales/sl.cjs | safe | No malicious patterns detected; the file is a standard localization module for the Zod validation library that only contains translation strings and error formatting logic. |
| v4/locales/sl.js | safe | Cleared by Jev triage; no further analysis needed |
| v4/locales/sv.cjs | safe | No malicious patterns detected; the file contains only standard Swedish localization strings and error message formatting logic for a validation library. |
| v4/locales/sv.js | safe | Cleared by Jev triage; no further analysis needed |
| v4/locales/ta.cjs | safe | No malicious patterns detected; the file contains only TypeScript/CommonJS interop helpers and Tamil locale error messages for a validation library. |
| v4/locales/ta.js | safe | Cleared by Jev triage; no further analysis needed |
| v4/locales/tg.cjs | safe | This is a legitimate Zod localization file for Tajik containing only static error message strings and standard TypeScript CommonJS interop helpers, with no network, filesystem, process, or dynamic execution activity. |
| v4/locales/tg.js | safe | Cleared by Jev triage; no further analysis needed |
| v4/locales/th.cjs | safe | No malicious patterns detected; this is a standard Zod Thai locale error translation module with only static data and no network, file system, or process operations. |
| v4/locales/th.js | safe | Cleared by Jev triage; no further analysis needed |
| v4/locales/tk.cjs | safe | This is a standard localization/translation file for validation error messages with no malicious patterns, network activity, or dynamic code execution. |
| v4/locales/tk.js | safe | Cleared by Jev triage; no further analysis needed |
| v4/locales/tr.cjs | safe | No malicious patterns detected in the locale file; it contains only TypeScript helper functions and Turkish error message definitions for a validation library. |
| v4/locales/tr.js | safe | Cleared by Jev triage; no further analysis needed |
| v4/locales/ua.cjs | safe | No malicious patterns detected; the code is a simple deprecated alias to the Ukrainian locale module. |
| v4/locales/ua.js | safe | Cleared by Jev triage; no further analysis needed |
| v4/locales/uk.cjs | safe | This is a legitimate Zod locale error message file for Ukrainian with no malicious patterns detected. |
| v4/locales/uk.js | safe | Cleared by Jev triage; no further analysis needed |
| v4/locales/ur.cjs | safe | This file contains only localization/error message strings for the Urdu locale of the Zod validation library and exhibits no malicious behavior, network access, credential harvesting, or dynamic code execution. |
| v4/locales/ur.js | safe | Cleared by Jev triage; no further analysis needed |
| v4/locales/uz.cjs | safe | No malicious patterns detected; this is a standard locale error message file for the Zod validation library. |
| v4/locales/uz.js | safe | Cleared by Jev triage; no further analysis needed |
| v4/locales/vi.cjs | safe | No malicious patterns detected |
| v4/locales/vi.js | safe | Cleared by Jev triage; no further analysis needed |
| v4/locales/yo.cjs | safe | No malicious patterns detected; the file is a standard Zod locale definition with no network, filesystem, or dynamic code execution activity. |
| v4/locales/yo.js | safe | Cleared by Jev triage; no further analysis needed |
| v4/locales/zh-CN.cjs | safe | This is a legitimate Zod locale file for Simplified Chinese error messages, containing only TypeScript-compiled helper boilerplate and pure translation/formatting logic with no malicious patterns. |
| v4/locales/zh-CN.js | safe | Cleared by Jev triage; no further analysis needed |
| v4/locales/zh-TW.cjs | safe | No malicious patterns detected; this is a legitimate localization/error message file for the Zod validation library. |
| v4/locales/zh-TW.js | safe | Cleared by Jev triage; no further analysis needed |
| v4/mini/checks.cjs | safe | This file is a standard re-export module for a validation library; it contains no malicious patterns, network activity, process execution, or dynamic code evaluation. |
| v4/mini/checks.js | safe | The file simply re-exports validation functions from a relative module with no suspicious behavior. |
| v4/mini/coerce.cjs | safe | No malicious patterns detected; the code is standard TypeScript-compiled CommonJS module bindings with a harmless export-sealing IIFE. |
| v4/mini/coerce.js | safe | Cleared by Jev triage; no further analysis needed |
| v4/mini/deep-partial.cjs | safe | The file is a standard TypeScript-to-CommonJS compilation output implementing a deepPartial utility for Zod schemas with no malicious patterns; the only import-time code freezes exports, which is harmless. |
| v4/mini/deep-partial.js | safe | Cleared by Jev triage; no further analysis needed |
| v4/mini/external.cjs | safe | This is standard TypeScript/CommonJS module re-export boilerplate for the Zod validation library; no malicious patterns detected. |
| v4/mini/external.js | safe | Cleared by Jev triage; no further analysis needed |
| v4/mini/in-out.cjs | safe | The file contains standard TypeScript helper functions for Zod schema input/output handling and an export sealing routine, with no malicious patterns such as data exfiltration, credential harvesting, obfuscation, dynamic code execution, or process spawning. |
| v4/mini/in-out.js | safe | Cleared by Jev triage; no further analysis needed |
| v4/mini/index.cjs | safe | No malicious patterns detected; the code is a standard CommonJS interop helper with export sealing and contains no data exfiltration, obfuscation, or dynamic code execution. |
| v4/mini/index.js | safe | Cleared by Jev triage; no further analysis needed |
| v4/mini/iso.cjs | safe | Legitimate Zod Mini ISO date/time validation module with no malicious patterns detected |
| v4/mini/iso.js | safe | No malicious patterns detected; the file only defines Zod Mini ISO validation schemas using internal imports and constructors. |
| v4/mini/parse.cjs | safe | No malicious patterns detected; the only notable behavior is a benign import-time export-sealing routine with no exfiltration, credential harvesting, obfuscation, or network/process/file-system activity. |
| v4/mini/parse.js | safe | Cleared by Jev triage; no further analysis needed |
| v4/mini/schemas.js | safe | No malicious patterns detected in the Zod Mini schema definitions; all code is legitimate schema/validation logic with no exfiltration, dynamic execution, process spawning, or credential access. |
Affected version ranges
1 of 4 scanned versions of zod are flagged: 4.6.5 (critical). The latest scanned version, 4.6.5, is critical risk. Only versions we have scanned are listed; unscanned versions between them are not covered.
| Versions | Verdict | Count | Range | Top findings |
|---|---|---|---|---|
| 4.6.5 | Critical | 1 | 4.6.5 | Dynamic code execution; Dynamic code execution via new Function |
| 3.25.76 โ 4.1.13 | Needs review | 2 | >=3.25.76 <=4.1.13 | Dynamic code execution; Dynamic code execution via Function constructor |
| 3.23.8 | Not scanned | 1 | 3.23.8 | |
| 3.22.4 | No issues | 1 | 3.22.4 |
Flagged files across versions
- critical v4/core/checks.cjs: present in 4.6.5
- critical
v4/core/doc.cjs (Dynamic code execution)
NPS-9534A8F558A8: present in 4.6.5
Full list, including published versions not scanned yet: version ranges API.
Scanned versions of zod
Frequently asked questions
Is zod safe to use?
zod@4.6.5 has 1 critical, 3 high, 12 medium, 46 low severity findings, including behavior that is dangerous or likely malicious. Do not install it without reviewing the findings.
Does zod contain malware?
The latest scan of zod (4.6.5) flagged critical behavior consistent with malicious or dangerous code. See the findings on this page for the exact files and lines.
How was zod checked?
Togoder Security downloaded the published npm package and had an AI model read its 375 source files, looking for install scripts, credential access, network exfiltration, obfuscation, backdoors and crypto-wallet theft. The results are cached by file hash and shown here.
How do I scan zod together with the rest of my dependencies?
Upload your lockfile at https://security.togoder.click/scan or call the API documented at https://security.togoder.click/api-docs. Files that have already been scanned, like the ones in zod@4.6.5, cost nothing.