Togoder security

npm package security report

zod@3.25.76 security report

Risky patterns found that deserve a look.

Needs review Version 3.25.76 Files reviewed 271 Size 2.1 MB Scanned

Summary

Togoder Security scanned the npm package zod@3.25.76 on Oct 4, 2026. An AI review of 271 source files produced 1 high, 2 medium, 8 low severity findings. The overall verdict is medium: the findings flag risky but common patterns (dynamic code, unsafe defaults, broad file or network access) rather than confirmed malware.

0
critical
1
high
2
medium
8
low

Findings 11

high

Dynamic code execution

NPS-EB9A0FECE2ED

The compile() method retrieves the Function constructor indirectly via const F = Function; and invokes it via new F(...args, lines.join("\n")). This builds a new function from dynamically assembled source code (args and content), which is functionally equivalent to eval/new Function. If args or content can ever be influenced by untrusted input (e.g., user data, remote config, environment-derived strings), this becomes an arbitrary code execution sink. The indirect assignment is a mild obfuscation pattern that can evade naive static scanners looking only for the literal new Function(...).

v4/core/doc.cjs:36
medium

Dynamic code execution via Function constructor

NPS-5CD1785B0ABA

The compile() method uses new Function(...args, ...) to dynamically construct a JavaScript function from strings. While this appears to be a legitimate code-generation utility (similar to the tsup/esbuild/esrap Doc pattern used by tools like dedent/magic-string), the ability to compile arbitrary strings into executable functions is inherently dangerous if args or content ever derive from untrusted input. It is not obfuscated and no encoded payload is present, but it is a dynamic-code-execution primitive that should be flagged.

src/v4/core/doc.ts:40
medium

Dynamic code execution

NPS-1E85D0FE4531

The compile() method uses the Function constructor to dynamically compile and execute arbitrary code from the args and content properties. This can lead to code injection if untrusted input reaches these fields, effectively behaving like eval.

v4/core/doc.js:33
low

Dual sync/async execution of caller-supplied function

NPS-E949D5582ADD

In write(arg), if arg is a function it is invoked twice: once with { execution: "sync" } and once with { execution: "async" }. This pattern mirrors documented magicast/ast-types-style code generation usage, but invoking a callback twice with the same Doc instance and different flags is a control-flow oddity worth reviewing: a callback that mutates this.content non-idempotently can duplicate or corrupt generated code, and the async pass suggests execution paths not fully visible in this file.

v4/core/doc.cjs:18
low

Dynamic Code Execution

NPS-C84285437DA7

The code uses doc.compile() which invokes new Function() internally to generate optimized parsing functions for Zod object schemas (JIT compilation). This is a legitimate performance optimization feature of Zod, guarded by allowsEval.value which checks if eval is permitted. The generated code is constructed from internally controlled schema definitions, not from user input.

v4/core/schemas.cjs
low

Potential Prototype Pollution Protection

NPS-45FCBDA0E101

The $ZodRecord parser explicitly skips the __proto__ key (if (key === "__proto__") continue;), demonstrating defensive coding against prototype pollution. No malicious exploitation patterns present.

v4/core/schemas.cjs
low

dynamic code generation

NPS-54A33C3EAADC

The code uses doc.compile() in generateFastpass to generate and execute JavaScript code dynamically at runtime for performance optimization. While this is part of Zod's JIT compilation feature and not inherently malicious, it is a form of dynamic code execution that could be abused if inputs were attacker-controlled. The generated code is based on schema shape keys and uses util.esc() for escaping, reducing risk.

v4/core/schemas.js:660
low

use of eval-like behavior

NPS-6FDDA83DBFF7

The Doc class from ./doc.js is used to compile a function from a string. This is effectively an eval-like mechanism. In this context it is used for performance optimization of object parsing, and the generated code is derived from schema definitions rather than user input. However, it still represents a dynamic code execution surface.

v4/core/schemas.js:660
low

eval usage

NPS-5F38D0CC7BAA

The allowsEval function uses new Function("") to test if eval is allowed. This is a common pattern in libraries to feature-detect CSP restrictions rather than to execute malicious code. No user-controlled input is passed to the Function constructor.

v4/core/util.cjs:117
low

Static locale/error message definitions

NPS-42407B8B68AE

The file only contains Hebrew translation strings for validation library error messages. There is no network access, file system access, environment variable reading, or process spawning.

v4/locales/he.cjs
low

Standard TypeScript/CommonJS interop boilerplate

NPS-4D52083301E7

The __createBinding, __setModuleDefault, and __importStar helpers are standard TypeScript compiler-generated code for interop. No obfuscation, eval, or dynamic code execution is present.

v4/locales/he.cjs:1

Files reviewed

FileVerdictWhat the reviewer saw
src/v4/core/doc.ts medium A code-generation helper that uses new Function to compile generated source strings; no exfiltration, credential harvesting, network calls, process spawning, or install-time execution was found, but the dynamic-eval primitive warrants a warning.
v4/core/doc.cjs medium File contains dynamic function construction via the Function constructor with assembled source and an unusual dual sync/async callback invocation, but no network, filesystem, environment harvesting, or process-spawning behavior was observed.
v4/core/doc.js medium The file uses dynamic code generation via the Function constructor, which is a potential code injection risk, but no other malicious patterns were detected.
v4/core/schemas.js medium The code is legitimate Zod schema validation logic with a JIT compilation feature that dynamically generates functions; no malicious patterns such as data exfiltration, credential harvesting, or backdoors were detected.
index.cjs safe No malicious patterns detected; the file contains only standard TypeScript/CommonJS interoperability helpers and re-exports from a local module.
index.js safe Cleared by Jev triage; no further analysis needed
src/index.ts safe Cleared by Jev triage; no further analysis needed
src/v3/ZodError.ts safe Cleared by Jev triage; no further analysis needed
src/v3/benchmarks/datetime.ts safe Cleared by Jev triage; no further analysis needed
src/v3/benchmarks/discriminatedUnion.ts safe Cleared by Jev triage; no further analysis needed
src/v3/benchmarks/index.ts safe No malicious patterns detected; the file is a standard benchmark runner that reads CLI arguments and runs in-memory benchmarks without network, filesystem, or process-spawning operations.
src/v3/benchmarks/ipv4.ts safe Cleared by Jev triage; no further analysis needed
src/v3/benchmarks/object.ts safe Cleared by Jev triage; no further analysis needed
src/v3/benchmarks/primitives.ts safe Cleared by Jev triage; no further analysis needed
src/v3/benchmarks/realworld.ts safe No malicious patterns detected; the code is a standard Zod validation benchmark with no network, filesystem, process, or obfuscated behavior.
src/v3/benchmarks/string.ts safe Cleared by Jev triage; no further analysis needed
src/v3/benchmarks/union.ts safe Cleared by Jev triage; no further analysis needed
src/v3/errors.ts safe Cleared by Jev triage; no further analysis needed
src/v3/external.ts safe Cleared by Jev triage; no further analysis needed
src/v3/helpers/enumUtil.ts safe Cleared by Jev triage; no further analysis needed
src/v3/helpers/errorUtil.ts safe Cleared by Jev triage; no further analysis needed
src/v3/helpers/parseUtil.ts safe Cleared by Jev triage; no further analysis needed
src/v3/helpers/partialUtil.ts safe Cleared by Jev triage; no further analysis needed
src/v3/helpers/typeAliases.ts safe Cleared by Jev triage; no further analysis needed
src/v3/helpers/util.ts safe Cleared by Jev triage; no further analysis needed
Show 246 more files
FileVerdictWhat the reviewer saw
src/v3/index.ts safe Cleared by Jev triage; no further analysis needed
src/v3/locales/en.ts safe Cleared by Jev triage; no further analysis needed
src/v3/standard-schema.ts safe Cleared by Jev triage; no further analysis needed
src/v4-mini/index.ts safe Cleared by Jev triage; no further analysis needed
src/v4/classic/checks.ts safe Cleared by Jev triage; no further analysis needed
src/v4/classic/coerce.ts safe Cleared by Jev triage; no further analysis needed
src/v4/classic/compat.ts safe Cleared by Jev triage; no further analysis needed
src/v4/classic/errors.ts safe Cleared by Jev triage; no further analysis needed
src/v4/classic/external.ts safe This is a standard Zod v4 re-export module that only re-exports types and functions from internal modules; no malicious patterns detected.
src/v4/classic/index.ts safe Cleared by Jev triage; no further analysis needed
src/v4/classic/iso.ts safe Cleared by Jev triage; no further analysis needed
src/v4/classic/parse.ts safe Cleared by Jev triage; no further analysis needed
src/v4/classic/schemas.ts safe Cleared by Jev triage; no further analysis needed
src/v4/core/api.ts safe Cleared by Jev triage; no further analysis needed
src/v4/core/checks.ts safe Cleared by Jev triage; no further analysis needed
src/v4/core/config.ts safe Cleared by Jev triage; no further analysis needed
src/v4/core/core.ts safe No malicious patterns detected; the code is a legitimate Zod schema constructor utility with no network, filesystem, process, or dynamic code execution concerns.
src/v4/core/errors.ts safe Cleared by Jev triage; no further analysis needed
src/v4/core/function.ts safe Cleared by Jev triage; no further analysis needed
src/v4/core/index.ts safe Cleared by Jev triage; no further analysis needed
src/v4/core/json-schema.ts safe Cleared by Jev triage; no further analysis needed
src/v4/core/parse.ts safe Cleared by Jev triage; no further analysis needed
src/v4/core/regexes.ts safe No malicious patterns detected
src/v4/core/registries.ts safe Cleared by Jev triage; no further analysis needed
src/v4/core/standard-schema.ts safe Cleared by Jev triage; no further analysis needed
src/v4/core/to-json-schema.ts safe No malicious patterns detected; the code is a legitimate JSON Schema generator for Zod with no network, filesystem, process execution, or obfuscation concerns.
src/v4/core/util.ts safe No malicious patterns detected
src/v4/core/versions.ts safe Cleared by Jev triage; no further analysis needed
src/v4/core/zsf.ts safe Cleared by Jev triage; no further analysis needed
src/v4/index.ts safe Cleared by Jev triage; no further analysis needed
src/v4/locales/ar.ts safe Cleared by Jev triage; no further analysis needed
src/v4/locales/az.ts safe Cleared by Jev triage; no further analysis needed
src/v4/locales/be.ts safe Cleared by Jev triage; no further analysis needed
src/v4/locales/ca.ts safe Cleared by Jev triage; no further analysis needed
src/v4/locales/cs.ts safe Cleared by Jev triage; no further analysis needed
src/v4/locales/de.ts safe Cleared by Jev triage; no further analysis needed
src/v4/locales/en.ts safe Cleared by Jev triage; no further analysis needed
src/v4/locales/eo.ts safe Cleared by Jev triage; no further analysis needed
src/v4/locales/es.ts safe Cleared by Jev triage; no further analysis needed
src/v4/locales/fa.ts safe Cleared by Jev triage; no further analysis needed
src/v4/locales/fi.ts safe Cleared by Jev triage; no further analysis needed
src/v4/locales/fr-CA.ts safe Cleared by Jev triage; no further analysis needed
src/v4/locales/fr.ts safe Cleared by Jev triage; no further analysis needed
src/v4/locales/he.ts safe Cleared by Jev triage; no further analysis needed
src/v4/locales/hu.ts safe Cleared by Jev triage; no further analysis needed
src/v4/locales/id.ts safe Cleared by Jev triage; no further analysis needed
src/v4/locales/index.ts safe Cleared by Jev triage; no further analysis needed
src/v4/locales/it.ts safe Cleared by Jev triage; no further analysis needed
src/v4/locales/ja.ts safe Cleared by Jev triage; no further analysis needed
src/v4/locales/kh.ts safe Cleared by Jev triage; no further analysis needed
src/v4/locales/ko.ts safe Cleared by Jev triage; no further analysis needed
src/v4/locales/mk.ts safe Cleared by Jev triage; no further analysis needed
src/v4/locales/ms.ts safe Cleared by Jev triage; no further analysis needed
src/v4/locales/nl.ts safe Cleared by Jev triage; no further analysis needed
src/v4/locales/no.ts safe Cleared by Jev triage; no further analysis needed
src/v4/locales/ota.ts safe Cleared by Jev triage; no further analysis needed
src/v4/locales/pl.ts safe Cleared by Jev triage; no further analysis needed
src/v4/locales/ps.ts safe Cleared by Jev triage; no further analysis needed
src/v4/locales/pt.ts safe Cleared by Jev triage; no further analysis needed
src/v4/locales/ru.ts safe Cleared by Jev triage; no further analysis needed
src/v4/locales/sl.ts safe Cleared by Jev triage; no further analysis needed
src/v4/locales/sv.ts safe Cleared by Jev triage; no further analysis needed
src/v4/locales/ta.ts safe Cleared by Jev triage; no further analysis needed
src/v4/locales/th.ts safe Cleared by Jev triage; no further analysis needed
src/v4/locales/tr.ts safe Cleared by Jev triage; no further analysis needed
src/v4/locales/ua.ts safe Cleared by Jev triage; no further analysis needed
src/v4/locales/ur.ts safe Cleared by Jev triage; no further analysis needed
src/v4/locales/vi.ts safe Cleared by Jev triage; no further analysis needed
src/v4/locales/zh-CN.ts safe Cleared by Jev triage; no further analysis needed
src/v4/locales/zh-TW.ts safe Cleared by Jev triage; no further analysis needed
src/v4/mini/checks.ts safe Cleared by Jev triage; no further analysis needed
src/v4/mini/coerce.ts safe Cleared by Jev triage; no further analysis needed
src/v4/mini/external.ts safe Cleared by Jev triage; no further analysis needed
src/v4/mini/index.ts safe Cleared by Jev triage; no further analysis needed
src/v4/mini/iso.ts safe Cleared by Jev triage; no further analysis needed
src/v4/mini/parse.ts safe Cleared by Jev triage; no further analysis needed
src/v4/mini/schemas.ts safe Cleared by Jev triage; no further analysis needed
v3/ZodError.cjs safe No malicious patterns detected; the file is a standard Zod error handling module with no network, file system, or code execution activity.
v3/ZodError.js safe Cleared by Jev triage; no further analysis needed
v3/errors.cjs safe No malicious patterns detected; the file only manages error message localization maps without network, filesystem, or process operations.
v3/errors.js safe Cleared by Jev triage; no further analysis needed
v3/external.cjs safe No malicious patterns detected; this file only contains standard TypeScript CommonJS re-export boilerplate.
v3/external.js safe Cleared by Jev triage; no further analysis needed
v3/helpers/enumUtil.cjs safe No malicious patterns detected
v3/helpers/enumUtil.js safe Cleared by Jev triage; no further analysis needed
v3/helpers/errorUtil.cjs safe No malicious patterns detected
v3/helpers/errorUtil.js safe No malicious patterns detected; the code is a simple utility for converting error messages to objects or strings.
v3/helpers/parseUtil.cjs safe No malicious patterns detected; the file contains only standard validation and error-handling utilities from a Zod-like library.
v3/helpers/parseUtil.js safe Cleared by Jev triage; no further analysis needed
v3/helpers/partialUtil.cjs safe No malicious patterns detected
v3/helpers/partialUtil.js safe Cleared by Jev triage; no further analysis needed
v3/helpers/typeAliases.cjs safe No malicious patterns detected
v3/helpers/typeAliases.js safe Cleared by Jev triage; no further analysis needed
v3/helpers/util.cjs safe The code is a utility module for the Zod validation library and contains no malicious patterns, network calls, file system access, or dynamic code execution.
v3/helpers/util.js safe No malicious patterns detected
v3/index.cjs safe No malicious patterns detected
v3/index.js safe Cleared by Jev triage; no further analysis needed
v3/locales/en.cjs safe Cleared by Jev triage; no further analysis needed
v3/locales/en.js safe Cleared by Jev triage; no further analysis needed
v3/standard-schema.cjs safe No malicious patterns detected
v3/standard-schema.js safe Cleared by Jev triage; no further analysis needed
v4-mini/index.cjs safe No malicious patterns detected; the file is a standard TypeScript-generated CommonJS re-export shim.
v4-mini/index.js safe Cleared by Jev triage; no further analysis needed
v4/classic/checks.cjs safe This module is a simple re-export shim that exclusively re-exports validation check functions from a sibling core module with no dynamic execution, network, filesystem, or process activity.
v4/classic/checks.js safe Cleared by Jev triage; no further analysis needed
v4/classic/coerce.cjs safe No malicious patterns detected; the code is standard TypeScript-compiled helper functions for Zod schema coercion with no suspicious behavior.
v4/classic/coerce.js safe Cleared by Jev triage; no further analysis needed
v4/classic/compat.cjs safe This is a standard TypeScript-generated Zod v3 compatibility layer with no malicious patterns detected.
v4/classic/compat.js safe Cleared by Jev triage; no further analysis needed
v4/classic/errors.cjs safe No malicious patterns detected; the code is standard TypeScript/CommonJS interop and Zod error class definition with no exfiltration, obfuscation, or process spawning.
v4/classic/errors.js safe Cleared by Jev triage; no further analysis needed
v4/classic/external.cjs safe This is standard TypeScript/CommonJS interop boilerplate from the Zod validation library, with no malicious patterns detected.
v4/classic/external.js safe This file is a standard module export aggregator for the Zod validation library; no malicious patterns, dynamic execution, network calls, or install-time behavior were detected.
v4/classic/index.cjs safe No malicious patterns detected
v4/classic/index.js safe Cleared by Jev triage; no further analysis needed
v4/classic/iso.cjs safe No malicious patterns detected; the code is a standard TypeScript-compiled Zod library module for ISO date/time schemas with only benign module import/export logic.
v4/classic/iso.js safe No malicious patterns detected
v4/classic/parse.cjs safe No malicious patterns detected
v4/classic/parse.js safe Cleared by Jev triage; no further analysis needed
v4/classic/schemas.cjs safe No malicious patterns detected; this is a legitimate Zod schema definition module with standard TypeScript compilation helpers and no suspicious behavior.
v4/classic/schemas.js safe No malicious patterns detected
v4/core/api.cjs safe No malicious patterns detected; the file is a standard Zod v4 validation API module with only internal schema/check construction and no network, filesystem, process, or dynamic execution behavior.
v4/core/api.js safe Cleared by Jev triage; no further analysis needed
v4/core/checks.cjs safe No malicious patterns detected; this is standard Zod validation check implementation code with no exfiltration, credential harvesting, obfuscation, or suspicious behavior.
v4/core/checks.js safe No malicious patterns detected; the code is a standard Zod validation library implementation with no exfiltration, obfuscation, or suspicious behavior.
v4/core/core.cjs safe No malicious patterns detected
v4/core/core.js safe No malicious patterns detected
v4/core/errors.cjs safe No malicious patterns detected; the file contains standard TypeScript/JavaScript module interop helpers and Zod error formatting utilities.
v4/core/errors.js safe Cleared by Jev triage; no further analysis needed
v4/core/function.cjs safe No malicious patterns detected
v4/core/function.js safe No malicious patterns detected; the code is a legitimate Zod schema function implementation with no external I/O, dynamic code execution, or credential harvesting.
v4/core/index.cjs safe No malicious patterns detected
v4/core/index.js safe Cleared by Jev triage; no further analysis needed
v4/core/json-schema.cjs safe No malicious patterns detected
v4/core/json-schema.js safe Cleared by Jev triage; no further analysis needed
v4/core/parse.cjs safe No malicious patterns detected; the file is standard Zod validation logic with TypeScript interop helpers.
v4/core/parse.js safe No malicious patterns detected
v4/core/regexes.cjs safe No malicious patterns detected; the file only exports regular expressions and helper functions for data validation.
v4/core/regexes.js safe No malicious patterns detected; the file contains only regular expression definitions and a UUID regex factory function.
v4/core/registries.cjs safe No malicious patterns detected
v4/core/registries.js safe Cleared by Jev triage; no further analysis needed
v4/core/schemas.cjs safe This is a legitimate Zod v4 validation library source file with no malicious patterns; the only noteworthy use of dynamic function generation is a documented performance optimization for object schema parsing, controlled entirely by internal schema definitions.
v4/core/standard-schema.cjs safe No malicious patterns detected
v4/core/standard-schema.js safe Cleared by Jev triage; no further analysis needed
v4/core/to-json-schema.cjs safe No malicious patterns detected; the code is a legitimate JSON Schema generator for Zod schema definitions with no network, filesystem, process, or obfuscation concerns.
v4/core/to-json-schema.js safe No malicious patterns detected; the code is a legitimate JSON Schema generator with no network, filesystem, credential, or code-execution red flags.
v4/core/util.cjs safe No malicious patterns detected; the only dynamic code execution is a benign feature-detection use of new Function.
v4/core/util.js safe No malicious patterns detected; the code contains standard utility functions from Zod library with no security concerns.
v4/core/versions.cjs safe No malicious patterns detected
v4/core/versions.js safe Cleared by Jev triage; no further analysis needed
v4/index.cjs safe No malicious patterns detected
v4/index.js safe Cleared by Jev triage; no further analysis needed
v4/locales/ar.cjs safe This file is a standard TypeScript-compiled localization module containing only Arabic translation strings and error message formatting utilities, with no malicious patterns detected.
v4/locales/ar.js safe Cleared by Jev triage; no further analysis needed
v4/locales/az.cjs safe This is a standard Zod library locale file for Azerbaijani translations containing only error message formatting logic with no malicious patterns.
v4/locales/az.js safe Cleared by Jev triage; no further analysis needed
v4/locales/be.cjs safe No malicious patterns detected; the file is a standard localization module for Belarusian error messages with no network, filesystem, process, or dynamic code execution activity.
v4/locales/be.js safe Cleared by Jev triage; no further analysis needed
v4/locales/ca.cjs safe No malicious patterns detected; the file is a standard localization module for validation error messages in Catalan with no network, filesystem, process, or dynamic code execution activity.
v4/locales/ca.js safe Cleared by Jev triage; no further analysis needed
v4/locales/cs.cjs safe No malicious patterns detected
v4/locales/cs.js safe Cleared by Jev triage; no further analysis needed
v4/locales/de.cjs safe No malicious patterns detected; this is a German locale translation file for the Zod validation library with only static error message strings and standard TypeScript helper functions.
v4/locales/de.js safe Cleared by Jev triage; no further analysis needed
v4/locales/en.cjs safe No malicious patterns detected
v4/locales/en.js safe Cleared by Jev triage; no further analysis needed
v4/locales/eo.cjs safe No malicious patterns detected
v4/locales/eo.js safe Cleared by Jev triage; no further analysis needed
v4/locales/es.cjs safe This file is a Spanish locale error message definition for a validation library, containing only static string tables and pure translation logic with no network, filesystem, process, or dynamic execution activity.
v4/locales/es.js safe Cleared by Jev triage; no further analysis needed
v4/locales/fa.cjs safe This file is a standard internationalization (i18n) locale definition for error messages in Persian; it contains no malicious patterns, network activity, file system access, or dynamic code execution.
v4/locales/fa.js safe Cleared by Jev triage; no further analysis needed
v4/locales/fi.cjs safe No malicious patterns detected; the file is a standard localization module for the Zod validation library containing only Finnish error message translations and harmless utility imports.
v4/locales/fi.js safe Cleared by Jev triage; no further analysis needed
v4/locales/fr-CA.cjs safe This is a standard TypeScript/CommonJS locale translation file for a validation library, containing only static error message strings and no malicious patterns.
v4/locales/fr-CA.js safe Cleared by Jev triage; no further analysis needed
v4/locales/fr.cjs safe This is a localization file for French error messages with standard TypeScript helper functions and no malicious patterns.
v4/locales/fr.js safe Cleared by Jev triage; no further analysis needed
v4/locales/he.cjs safe No malicious patterns detected; this is a benign localization file for Zod validation error messages.
v4/locales/he.js safe Cleared by Jev triage; no further analysis needed
v4/locales/hu.cjs safe No malicious patterns detected
v4/locales/hu.js safe Cleared by Jev triage; no further analysis needed
v4/locales/id.cjs safe No malicious patterns detected; the file is a localization module for error messages in Indonesian with no network, filesystem, or dynamic code execution concerns.
v4/locales/id.js safe Cleared by Jev triage; no further analysis needed
v4/locales/index.cjs safe No malicious patterns detected; the file is a standard locale export index with only static requires and property definitions.
v4/locales/index.js safe Cleared by Jev triage; no further analysis needed
v4/locales/it.cjs safe No malicious patterns detected; this is a legitimate Italian localization file for the Zod validation library containing only TypeScript helper boilerplate and error message translations.
v4/locales/it.js safe Cleared by Jev triage; no further analysis needed
v4/locales/ja.cjs safe No malicious patterns detected; the file is a standard localization module for Japanese error messages with only benign TypeScript-to-CommonJS helper boilerplate.
v4/locales/ja.js safe Cleared by Jev triage; no further analysis needed
v4/locales/kh.cjs safe No malicious patterns detected
v4/locales/kh.js safe Cleared by Jev triage; no further analysis needed
v4/locales/ko.cjs safe No malicious patterns detected; the file is a standard localization module for Zod error messages in Korean with no network, filesystem, or dynamic execution behavior.
v4/locales/ko.js safe Cleared by Jev triage; no further analysis needed
v4/locales/mk.cjs safe This file is a standard TypeScript-generated locale translation module for validation error messages, with no network, filesystem, process, or dynamic code execution activity.
v4/locales/mk.js safe Cleared by Jev triage; no further analysis needed
v4/locales/ms.cjs safe No malicious patterns detected; the file contains only standard TypeScript-compiled localization error messages with no network, filesystem, process, or dynamic code execution activity.
v4/locales/ms.js safe Cleared by Jev triage; no further analysis needed
v4/locales/nl.cjs safe No malicious patterns detected
v4/locales/nl.js safe Cleared by Jev triage; no further analysis needed
v4/locales/no.cjs safe No malicious patterns detected
v4/locales/no.js safe Cleared by Jev triage; no further analysis needed
v4/locales/ota.cjs safe No malicious patterns detected
v4/locales/ota.js safe Cleared by Jev triage; no further analysis needed
v4/locales/pl.cjs safe No malicious patterns detected; this is a standard Zod locale translation file with only TypeScript helper boilerplate and static error message definitions.
v4/locales/pl.js safe Cleared by Jev triage; no further analysis needed
v4/locales/ps.cjs safe No malicious patterns detected; this is a legitimate Zod locale file containing only localization strings and error formatting logic.
v4/locales/ps.js safe Cleared by Jev triage; no further analysis needed
v4/locales/pt.cjs safe No malicious patterns detected; the file is a standard localized error message module with no network, filesystem, or dynamic code execution activity.
v4/locales/pt.js safe Cleared by Jev triage; no further analysis needed
v4/locales/ru.cjs safe No malicious patterns detected; the file is a standard Russian localization module for a validation library with only benign imports and formatting logic.
v4/locales/ru.js safe Cleared by Jev triage; no further analysis needed
v4/locales/sl.cjs safe No malicious patterns detected
v4/locales/sl.js safe Cleared by Jev triage; no further analysis needed
v4/locales/sv.cjs safe No malicious patterns detected
v4/locales/sv.js safe Cleared by Jev triage; no further analysis needed
v4/locales/ta.cjs safe No malicious patterns detected; the file contains standard localization error messages and module import helpers.
v4/locales/ta.js safe Cleared by Jev triage; no further analysis needed
v4/locales/th.cjs safe No malicious patterns detected; this is a legitimate Thai localization file for the Zod validation library.
v4/locales/th.js safe Cleared by Jev triage; no further analysis needed
v4/locales/tr.cjs safe No malicious patterns detected
v4/locales/tr.js safe Cleared by Jev triage; no further analysis needed
v4/locales/ua.cjs safe No malicious patterns detected; this is a standard localization file for the Zod validation library containing Ukrainian error messages.
v4/locales/ua.js safe Cleared by Jev triage; no further analysis needed
v4/locales/ur.cjs safe This is a localization/error message file for the Urdu language in a validation library (likely Zod), containing only static translations and no malicious patterns.
v4/locales/ur.js safe Cleared by Jev triage; no further analysis needed
v4/locales/vi.cjs safe No malicious patterns detected; the file is a standard localization module containing only error message strings and helper functions.
v4/locales/vi.js safe Cleared by Jev triage; no further analysis needed
v4/locales/zh-CN.cjs safe The file contains only standard TypeScript-generated CommonJS boilerplate and Chinese language localization strings for error messages, with no malicious patterns detected.
v4/locales/zh-CN.js safe Cleared by Jev triage; no further analysis needed
v4/locales/zh-TW.cjs safe No malicious patterns detected; this is a standard TypeScript-compiled locale file for a validation library containing only localized error messages.
v4/locales/zh-TW.js safe Cleared by Jev triage; no further analysis needed
v4/mini/checks.cjs safe No malicious patterns detected; the file only re-exports validator functions from the core module via safe property getters.
v4/mini/checks.js safe No malicious patterns detected; the file only re-exports validation functions from the core module.
v4/mini/coerce.cjs safe The file contains only standard TypeScript-to-CommonJS helpers and Zod schema coercion exports with no malicious patterns.
v4/mini/coerce.js safe Cleared by Jev triage; no further analysis needed
v4/mini/external.cjs safe No malicious patterns detected; this is a standard TypeScript-generated CommonJS module re-export file for the Zod library.
v4/mini/external.js safe Cleared by Jev triage; no further analysis needed
v4/mini/index.cjs safe The code is a standard TypeScript/CommonJS module re-export helper with no malicious patterns, external calls, or runtime execution beyond normal module loading.
v4/mini/index.js safe Cleared by Jev triage; no further analysis needed
v4/mini/iso.cjs safe No malicious patterns detected; the code is a standard TypeScript/CommonJS compilation artifact for the Zod Mini ISO date/time schema module.
v4/mini/iso.js safe No malicious patterns detected; the file only defines Zod ISO date/time validation constructors using internal core and schema imports.
v4/mini/parse.cjs safe No malicious patterns detected; the file is a simple re-export module with no dynamic execution, network calls, or filesystem access.
v4/mini/parse.js safe Cleared by Jev triage; no further analysis needed
v4/mini/schemas.cjs safe No malicious patterns detected in this Zod schema validation library file; it contains only standard TypeScript/JavaScript module initialization and schema definition code with no exfiltration, credential harvesting, obfuscation, or command execution.
v4/mini/schemas.js safe No malicious patterns detected; the file is a standard Zod schema definition module with no network, filesystem, process, or dynamic execution behaviors.

Affected version ranges

1 of 4 scanned versions of zod are flagged: 4.6.5 (critical). The latest scanned version, 4.6.5, is critical risk. Only versions we have scanned are listed; unscanned versions between them are not covered.

3.22.44.6.5
VersionsVerdictCountRangeTop findings
4.6.5 Critical 1 4.6.5 Dynamic code execution; Dynamic code execution via new Function
3.25.76 โ€“ 4.1.13 Needs review 2 >=3.25.76 <=4.1.13 Dynamic code execution; Dynamic code execution via Function constructor
3.23.8 Not scanned 1 3.23.8
3.22.4 No issues 1 3.22.4

Flagged files across versions

  • critical v4/core/checks.cjs: present in 4.6.5
  • critical v4/core/doc.cjs (Dynamic code execution) NPS-9534A8F558A8: present in 4.6.5

Full list, including published versions not scanned yet: version ranges API.

Scanned versions of zod

VersionVerdictFilesScanned
4.6.5 Critical risk 375 Oct 6, 2026
4.1.13 Needs review 298 Oct 4, 2026
3.25.76 Needs review 271 Oct 4, 2026
3.22.4 No issues 18 Oct 4, 2026

Frequently asked questions

Is zod safe to use?

No confirmed malware was found in zod@3.25.76, but the review flagged 1 high, 2 medium, 8 low severity findings for risky patterns worth checking before you rely on it.

Does zod contain malware?

No malware was identified in zod@3.25.76 when Togoder Security scanned it on Oct 4, 2026. A new version can still introduce malicious code, so scan the exact versions in your lockfile.

How was zod checked?

Togoder Security downloaded the published npm package and had an AI model read its 271 source files, looking for install scripts, credential access, network exfiltration, obfuscation, backdoors and crypto-wallet theft. The results are cached by file hash and shown here.

How do I scan zod together with the rest of my dependencies?

Upload your lockfile at https://security.togoder.click/scan or call the API documented at https://security.togoder.click/api-docs. Files that have already been scanned, like the ones in zod@3.25.76, cost nothing.

Related security reports