# zod@3.25.76 security report (npm)

- Verdict: **Needs review** (risk level: medium)
- Scanned: 2026-10-04T16:54:47.000Z
- Files reviewed: 271
- Findings: 1 high, 2 medium, 8 low severity findings
- Report: https://security.togoder.click/npm/zod@3.25.76
- Source: Togoder Security (https://security.togoder.click), AI source-code review

## Summary

Togoder Security scanned the npm package zod@3.25.76 on Oct 4, 2026. An AI review of 271 source files produced 1 high, 2 medium, 8 low severity findings. The overall verdict is medium: the findings flag risky but common patterns (dynamic code, unsafe defaults, broad file or network access) rather than confirmed malware.

## Findings

### [high] Dynamic code execution

Finding ID: `NPS-EB9A0FECE2ED`

File: `v4/core/doc.cjs:36`

The `compile()` method retrieves the `Function` constructor indirectly via `const F = Function;` and invokes it via `new F(...args, lines.join("\n"))`. This builds a new function from dynamically assembled source code (`args` and `content`), which is functionally equivalent to `eval`/`new Function`. If `args` or `content` can ever be influenced by untrusted input (e.g., user data, remote config, environment-derived strings), this becomes an arbitrary code execution sink. The indirect assignment is a mild obfuscation pattern that can evade naive static scanners looking only for the literal `new Function(...)`.

### [medium] Dynamic code execution via Function constructor

Finding ID: `NPS-5CD1785B0ABA`

File: `src/v4/core/doc.ts:40`

The compile() method uses `new Function(...args, ...)` to dynamically construct a JavaScript function from strings. While this appears to be a legitimate code-generation utility (similar to the `tsup`/`esbuild`/`esrap` Doc pattern used by tools like `dedent`/`magic-string`), the ability to compile arbitrary strings into executable functions is inherently dangerous if `args` or `content` ever derive from untrusted input. It is not obfuscated and no encoded payload is present, but it is a dynamic-code-execution primitive that should be flagged.

### [medium] Dynamic code execution

Finding ID: `NPS-1E85D0FE4531`

File: `v4/core/doc.js:33`

The `compile()` method uses the `Function` constructor to dynamically compile and execute arbitrary code from the `args` and `content` properties. This can lead to code injection if untrusted input reaches these fields, effectively behaving like `eval`.

### [low] Dual sync/async execution of caller-supplied function

Finding ID: `NPS-E949D5582ADD`

File: `v4/core/doc.cjs:18`

In `write(arg)`, if `arg` is a function it is invoked twice: once with `{ execution: "sync" }` and once with `{ execution: "async" }`. This pattern mirrors documented `magicast`/`ast-types`-style code generation usage, but invoking a callback twice with the same `Doc` instance and different flags is a control-flow oddity worth reviewing: a callback that mutates `this.content` non-idempotently can duplicate or corrupt generated code, and the `async` pass suggests execution paths not fully visible in this file.

### [low] Dynamic Code Execution

Finding ID: `NPS-C84285437DA7`

File: `v4/core/schemas.cjs`

The code uses `doc.compile()` which invokes `new Function()` internally to generate optimized parsing functions for Zod object schemas (JIT compilation). This is a legitimate performance optimization feature of Zod, guarded by `allowsEval.value` which checks if eval is permitted. The generated code is constructed from internally controlled schema definitions, not from user input.

### [low] Potential Prototype Pollution Protection

Finding ID: `NPS-45FCBDA0E101`

File: `v4/core/schemas.cjs`

The `$ZodRecord` parser explicitly skips the `__proto__` key (`if (key === "__proto__") continue;`), demonstrating defensive coding against prototype pollution. No malicious exploitation patterns present.

### [low] dynamic code generation

Finding ID: `NPS-54A33C3EAADC`

File: `v4/core/schemas.js:660`

The code uses `doc.compile()` in `generateFastpass` to generate and execute JavaScript code dynamically at runtime for performance optimization. While this is part of Zod's JIT compilation feature and not inherently malicious, it is a form of dynamic code execution that could be abused if inputs were attacker-controlled. The generated code is based on schema shape keys and uses `util.esc()` for escaping, reducing risk.

### [low] use of eval-like behavior

Finding ID: `NPS-6FDDA83DBFF7`

File: `v4/core/schemas.js:660`

The `Doc` class from `./doc.js` is used to compile a function from a string. This is effectively an `eval`-like mechanism. In this context it is used for performance optimization of object parsing, and the generated code is derived from schema definitions rather than user input. However, it still represents a dynamic code execution surface.

### [low] eval usage

Finding ID: `NPS-5F38D0CC7BAA`

File: `v4/core/util.cjs:117`

The `allowsEval` function uses `new Function("")` to test if eval is allowed. This is a common pattern in libraries to feature-detect CSP restrictions rather than to execute malicious code. No user-controlled input is passed to the Function constructor.

### [low] Static locale/error message definitions

Finding ID: `NPS-42407B8B68AE`

File: `v4/locales/he.cjs`

The file only contains Hebrew translation strings for validation library error messages. There is no network access, file system access, environment variable reading, or process spawning.

### [low] Standard TypeScript/CommonJS interop boilerplate

Finding ID: `NPS-4D52083301E7`

File: `v4/locales/he.cjs:1`

The __createBinding, __setModuleDefault, and __importStar helpers are standard TypeScript compiler-generated code for interop. No obfuscation, eval, or dynamic code execution is present.

## Files reviewed

- `src/v4/core/doc.ts` (medium): A code-generation helper that uses `new Function` to compile generated source strings; no exfiltration, credential harvesting, network calls, process spawning, or install-time execution was found, but the dynamic-eval primitive warrants a warning.
- `v4/core/doc.cjs` (medium): File contains dynamic function construction via the `Function` constructor with assembled source and an unusual dual sync/async callback invocation, but no network, filesystem, environment harvesting, or process-spawning behavior was observed.
- `v4/core/doc.js` (medium): The file uses dynamic code generation via the `Function` constructor, which is a potential code injection risk, but no other malicious patterns were detected.
- `v4/core/schemas.js` (medium): The code is legitimate Zod schema validation logic with a JIT compilation feature that dynamically generates functions; no malicious patterns such as data exfiltration, credential harvesting, or backdoors were detected.
- `index.cjs` (safe): No malicious patterns detected; the file contains only standard TypeScript/CommonJS interoperability helpers and re-exports from a local module.
- `index.js` (safe): Cleared by Jev triage; no further analysis needed
- `src/index.ts` (safe): Cleared by Jev triage; no further analysis needed
- `src/v3/ZodError.ts` (safe): Cleared by Jev triage; no further analysis needed
- `src/v3/benchmarks/datetime.ts` (safe): Cleared by Jev triage; no further analysis needed
- `src/v3/benchmarks/discriminatedUnion.ts` (safe): Cleared by Jev triage; no further analysis needed
- `src/v3/benchmarks/index.ts` (safe): No malicious patterns detected; the file is a standard benchmark runner that reads CLI arguments and runs in-memory benchmarks without network, filesystem, or process-spawning operations.
- `src/v3/benchmarks/ipv4.ts` (safe): Cleared by Jev triage; no further analysis needed
- `src/v3/benchmarks/object.ts` (safe): Cleared by Jev triage; no further analysis needed
- `src/v3/benchmarks/primitives.ts` (safe): Cleared by Jev triage; no further analysis needed
- `src/v3/benchmarks/realworld.ts` (safe): No malicious patterns detected; the code is a standard Zod validation benchmark with no network, filesystem, process, or obfuscated behavior.
- `src/v3/benchmarks/string.ts` (safe): Cleared by Jev triage; no further analysis needed
- `src/v3/benchmarks/union.ts` (safe): Cleared by Jev triage; no further analysis needed
- `src/v3/errors.ts` (safe): Cleared by Jev triage; no further analysis needed
- `src/v3/external.ts` (safe): Cleared by Jev triage; no further analysis needed
- `src/v3/helpers/enumUtil.ts` (safe): Cleared by Jev triage; no further analysis needed
- `src/v3/helpers/errorUtil.ts` (safe): Cleared by Jev triage; no further analysis needed
- `src/v3/helpers/parseUtil.ts` (safe): Cleared by Jev triage; no further analysis needed
- `src/v3/helpers/partialUtil.ts` (safe): Cleared by Jev triage; no further analysis needed
- `src/v3/helpers/typeAliases.ts` (safe): Cleared by Jev triage; no further analysis needed
- `src/v3/helpers/util.ts` (safe): Cleared by Jev triage; no further analysis needed
- `src/v3/index.ts` (safe): Cleared by Jev triage; no further analysis needed
- `src/v3/locales/en.ts` (safe): Cleared by Jev triage; no further analysis needed
- `src/v3/standard-schema.ts` (safe): Cleared by Jev triage; no further analysis needed
- `src/v4-mini/index.ts` (safe): Cleared by Jev triage; no further analysis needed
- `src/v4/classic/checks.ts` (safe): Cleared by Jev triage; no further analysis needed
- `src/v4/classic/coerce.ts` (safe): Cleared by Jev triage; no further analysis needed
- `src/v4/classic/compat.ts` (safe): Cleared by Jev triage; no further analysis needed
- `src/v4/classic/errors.ts` (safe): Cleared by Jev triage; no further analysis needed
- `src/v4/classic/external.ts` (safe): This is a standard Zod v4 re-export module that only re-exports types and functions from internal modules; no malicious patterns detected.
- `src/v4/classic/index.ts` (safe): Cleared by Jev triage; no further analysis needed
- `src/v4/classic/iso.ts` (safe): Cleared by Jev triage; no further analysis needed
- `src/v4/classic/parse.ts` (safe): Cleared by Jev triage; no further analysis needed
- `src/v4/classic/schemas.ts` (safe): Cleared by Jev triage; no further analysis needed
- `src/v4/core/api.ts` (safe): Cleared by Jev triage; no further analysis needed
- `src/v4/core/checks.ts` (safe): Cleared by Jev triage; no further analysis needed
- `src/v4/core/config.ts` (safe): Cleared by Jev triage; no further analysis needed
- `src/v4/core/core.ts` (safe): No malicious patterns detected; the code is a legitimate Zod schema constructor utility with no network, filesystem, process, or dynamic code execution concerns.
- `src/v4/core/errors.ts` (safe): Cleared by Jev triage; no further analysis needed
- `src/v4/core/function.ts` (safe): Cleared by Jev triage; no further analysis needed
- `src/v4/core/index.ts` (safe): Cleared by Jev triage; no further analysis needed
- `src/v4/core/json-schema.ts` (safe): Cleared by Jev triage; no further analysis needed
- `src/v4/core/parse.ts` (safe): Cleared by Jev triage; no further analysis needed
- `src/v4/core/regexes.ts` (safe): No malicious patterns detected
- `src/v4/core/registries.ts` (safe): Cleared by Jev triage; no further analysis needed
- `src/v4/core/standard-schema.ts` (safe): Cleared by Jev triage; no further analysis needed
- `src/v4/core/to-json-schema.ts` (safe): No malicious patterns detected; the code is a legitimate JSON Schema generator for Zod with no network, filesystem, process execution, or obfuscation concerns.
- `src/v4/core/util.ts` (safe): No malicious patterns detected
- `src/v4/core/versions.ts` (safe): Cleared by Jev triage; no further analysis needed
- `src/v4/core/zsf.ts` (safe): Cleared by Jev triage; no further analysis needed
- `src/v4/index.ts` (safe): Cleared by Jev triage; no further analysis needed
- `src/v4/locales/ar.ts` (safe): Cleared by Jev triage; no further analysis needed
- `src/v4/locales/az.ts` (safe): Cleared by Jev triage; no further analysis needed
- `src/v4/locales/be.ts` (safe): Cleared by Jev triage; no further analysis needed
- `src/v4/locales/ca.ts` (safe): Cleared by Jev triage; no further analysis needed
- `src/v4/locales/cs.ts` (safe): Cleared by Jev triage; no further analysis needed
- `src/v4/locales/de.ts` (safe): Cleared by Jev triage; no further analysis needed
- `src/v4/locales/en.ts` (safe): Cleared by Jev triage; no further analysis needed
- `src/v4/locales/eo.ts` (safe): Cleared by Jev triage; no further analysis needed
- `src/v4/locales/es.ts` (safe): Cleared by Jev triage; no further analysis needed
- `src/v4/locales/fa.ts` (safe): Cleared by Jev triage; no further analysis needed
- `src/v4/locales/fi.ts` (safe): Cleared by Jev triage; no further analysis needed
- `src/v4/locales/fr-CA.ts` (safe): Cleared by Jev triage; no further analysis needed
- `src/v4/locales/fr.ts` (safe): Cleared by Jev triage; no further analysis needed
- `src/v4/locales/he.ts` (safe): Cleared by Jev triage; no further analysis needed
- `src/v4/locales/hu.ts` (safe): Cleared by Jev triage; no further analysis needed
- `src/v4/locales/id.ts` (safe): Cleared by Jev triage; no further analysis needed
- `src/v4/locales/index.ts` (safe): Cleared by Jev triage; no further analysis needed
- `src/v4/locales/it.ts` (safe): Cleared by Jev triage; no further analysis needed
- `src/v4/locales/ja.ts` (safe): Cleared by Jev triage; no further analysis needed
- `src/v4/locales/kh.ts` (safe): Cleared by Jev triage; no further analysis needed
- `src/v4/locales/ko.ts` (safe): Cleared by Jev triage; no further analysis needed
- `src/v4/locales/mk.ts` (safe): Cleared by Jev triage; no further analysis needed
- `src/v4/locales/ms.ts` (safe): Cleared by Jev triage; no further analysis needed
- `src/v4/locales/nl.ts` (safe): Cleared by Jev triage; no further analysis needed
- `src/v4/locales/no.ts` (safe): Cleared by Jev triage; no further analysis needed
- `src/v4/locales/ota.ts` (safe): Cleared by Jev triage; no further analysis needed
- `src/v4/locales/pl.ts` (safe): Cleared by Jev triage; no further analysis needed
- `src/v4/locales/ps.ts` (safe): Cleared by Jev triage; no further analysis needed
- `src/v4/locales/pt.ts` (safe): Cleared by Jev triage; no further analysis needed
- `src/v4/locales/ru.ts` (safe): Cleared by Jev triage; no further analysis needed
- `src/v4/locales/sl.ts` (safe): Cleared by Jev triage; no further analysis needed
- `src/v4/locales/sv.ts` (safe): Cleared by Jev triage; no further analysis needed
- `src/v4/locales/ta.ts` (safe): Cleared by Jev triage; no further analysis needed
- `src/v4/locales/th.ts` (safe): Cleared by Jev triage; no further analysis needed
- `src/v4/locales/tr.ts` (safe): Cleared by Jev triage; no further analysis needed
- `src/v4/locales/ua.ts` (safe): Cleared by Jev triage; no further analysis needed
- `src/v4/locales/ur.ts` (safe): Cleared by Jev triage; no further analysis needed
- `src/v4/locales/vi.ts` (safe): Cleared by Jev triage; no further analysis needed
- `src/v4/locales/zh-CN.ts` (safe): Cleared by Jev triage; no further analysis needed
- `src/v4/locales/zh-TW.ts` (safe): Cleared by Jev triage; no further analysis needed
- `src/v4/mini/checks.ts` (safe): Cleared by Jev triage; no further analysis needed
- `src/v4/mini/coerce.ts` (safe): Cleared by Jev triage; no further analysis needed
- `src/v4/mini/external.ts` (safe): Cleared by Jev triage; no further analysis needed
- `src/v4/mini/index.ts` (safe): Cleared by Jev triage; no further analysis needed
- `src/v4/mini/iso.ts` (safe): Cleared by Jev triage; no further analysis needed
- `src/v4/mini/parse.ts` (safe): Cleared by Jev triage; no further analysis needed
- `src/v4/mini/schemas.ts` (safe): Cleared by Jev triage; no further analysis needed
- `v3/ZodError.cjs` (safe): No malicious patterns detected; the file is a standard Zod error handling module with no network, file system, or code execution activity.
- `v3/ZodError.js` (safe): Cleared by Jev triage; no further analysis needed
- `v3/errors.cjs` (safe): No malicious patterns detected; the file only manages error message localization maps without network, filesystem, or process operations.
- `v3/errors.js` (safe): Cleared by Jev triage; no further analysis needed
- `v3/external.cjs` (safe): No malicious patterns detected; this file only contains standard TypeScript CommonJS re-export boilerplate.
- `v3/external.js` (safe): Cleared by Jev triage; no further analysis needed
- `v3/helpers/enumUtil.cjs` (safe): No malicious patterns detected
- `v3/helpers/enumUtil.js` (safe): Cleared by Jev triage; no further analysis needed
- `v3/helpers/errorUtil.cjs` (safe): No malicious patterns detected
- `v3/helpers/errorUtil.js` (safe): No malicious patterns detected; the code is a simple utility for converting error messages to objects or strings.
- `v3/helpers/parseUtil.cjs` (safe): No malicious patterns detected; the file contains only standard validation and error-handling utilities from a Zod-like library.
- `v3/helpers/parseUtil.js` (safe): Cleared by Jev triage; no further analysis needed
- `v3/helpers/partialUtil.cjs` (safe): No malicious patterns detected
- `v3/helpers/partialUtil.js` (safe): Cleared by Jev triage; no further analysis needed
- `v3/helpers/typeAliases.cjs` (safe): No malicious patterns detected
- `v3/helpers/typeAliases.js` (safe): Cleared by Jev triage; no further analysis needed
- `v3/helpers/util.cjs` (safe): The code is a utility module for the Zod validation library and contains no malicious patterns, network calls, file system access, or dynamic code execution.
- `v3/helpers/util.js` (safe): No malicious patterns detected
- `v3/index.cjs` (safe): No malicious patterns detected
- `v3/index.js` (safe): Cleared by Jev triage; no further analysis needed
- `v3/locales/en.cjs` (safe): Cleared by Jev triage; no further analysis needed
- `v3/locales/en.js` (safe): Cleared by Jev triage; no further analysis needed
- `v3/standard-schema.cjs` (safe): No malicious patterns detected
- `v3/standard-schema.js` (safe): Cleared by Jev triage; no further analysis needed
- `v4-mini/index.cjs` (safe): No malicious patterns detected; the file is a standard TypeScript-generated CommonJS re-export shim.
- `v4-mini/index.js` (safe): Cleared by Jev triage; no further analysis needed
- `v4/classic/checks.cjs` (safe): This module is a simple re-export shim that exclusively re-exports validation check functions from a sibling core module with no dynamic execution, network, filesystem, or process activity.
- `v4/classic/checks.js` (safe): Cleared by Jev triage; no further analysis needed
- `v4/classic/coerce.cjs` (safe): No malicious patterns detected; the code is standard TypeScript-compiled helper functions for Zod schema coercion with no suspicious behavior.
- `v4/classic/coerce.js` (safe): Cleared by Jev triage; no further analysis needed
- `v4/classic/compat.cjs` (safe): This is a standard TypeScript-generated Zod v3 compatibility layer with no malicious patterns detected.
- `v4/classic/compat.js` (safe): Cleared by Jev triage; no further analysis needed
- `v4/classic/errors.cjs` (safe): No malicious patterns detected; the code is standard TypeScript/CommonJS interop and Zod error class definition with no exfiltration, obfuscation, or process spawning.
- `v4/classic/errors.js` (safe): Cleared by Jev triage; no further analysis needed
- `v4/classic/external.cjs` (safe): This is standard TypeScript/CommonJS interop boilerplate from the Zod validation library, with no malicious patterns detected.
- `v4/classic/external.js` (safe): This file is a standard module export aggregator for the Zod validation library; no malicious patterns, dynamic execution, network calls, or install-time behavior were detected.
- `v4/classic/index.cjs` (safe): No malicious patterns detected
- `v4/classic/index.js` (safe): Cleared by Jev triage; no further analysis needed
- `v4/classic/iso.cjs` (safe): No malicious patterns detected; the code is a standard TypeScript-compiled Zod library module for ISO date/time schemas with only benign module import/export logic.
- `v4/classic/iso.js` (safe): No malicious patterns detected
- `v4/classic/parse.cjs` (safe): No malicious patterns detected
- `v4/classic/parse.js` (safe): Cleared by Jev triage; no further analysis needed
- `v4/classic/schemas.cjs` (safe): No malicious patterns detected; this is a legitimate Zod schema definition module with standard TypeScript compilation helpers and no suspicious behavior.
- `v4/classic/schemas.js` (safe): No malicious patterns detected
- `v4/core/api.cjs` (safe): No malicious patterns detected; the file is a standard Zod v4 validation API module with only internal schema/check construction and no network, filesystem, process, or dynamic execution behavior.
- `v4/core/api.js` (safe): Cleared by Jev triage; no further analysis needed
- `v4/core/checks.cjs` (safe): No malicious patterns detected; this is standard Zod validation check implementation code with no exfiltration, credential harvesting, obfuscation, or suspicious behavior.
- `v4/core/checks.js` (safe): No malicious patterns detected; the code is a standard Zod validation library implementation with no exfiltration, obfuscation, or suspicious behavior.
- `v4/core/core.cjs` (safe): No malicious patterns detected
- `v4/core/core.js` (safe): No malicious patterns detected
- `v4/core/errors.cjs` (safe): No malicious patterns detected; the file contains standard TypeScript/JavaScript module interop helpers and Zod error formatting utilities.
- `v4/core/errors.js` (safe): Cleared by Jev triage; no further analysis needed
- `v4/core/function.cjs` (safe): No malicious patterns detected
- `v4/core/function.js` (safe): No malicious patterns detected; the code is a legitimate Zod schema function implementation with no external I/O, dynamic code execution, or credential harvesting.
- `v4/core/index.cjs` (safe): No malicious patterns detected
- `v4/core/index.js` (safe): Cleared by Jev triage; no further analysis needed
- `v4/core/json-schema.cjs` (safe): No malicious patterns detected
- `v4/core/json-schema.js` (safe): Cleared by Jev triage; no further analysis needed
- `v4/core/parse.cjs` (safe): No malicious patterns detected; the file is standard Zod validation logic with TypeScript interop helpers.
- `v4/core/parse.js` (safe): No malicious patterns detected
- `v4/core/regexes.cjs` (safe): No malicious patterns detected; the file only exports regular expressions and helper functions for data validation.
- `v4/core/regexes.js` (safe): No malicious patterns detected; the file contains only regular expression definitions and a UUID regex factory function.
- `v4/core/registries.cjs` (safe): No malicious patterns detected
- `v4/core/registries.js` (safe): Cleared by Jev triage; no further analysis needed
- `v4/core/schemas.cjs` (safe): This is a legitimate Zod v4 validation library source file with no malicious patterns; the only noteworthy use of dynamic function generation is a documented performance optimization for object schema parsing, controlled entirely by internal schema definitions.
- `v4/core/standard-schema.cjs` (safe): No malicious patterns detected
- `v4/core/standard-schema.js` (safe): Cleared by Jev triage; no further analysis needed
- `v4/core/to-json-schema.cjs` (safe): No malicious patterns detected; the code is a legitimate JSON Schema generator for Zod schema definitions with no network, filesystem, process, or obfuscation concerns.
- `v4/core/to-json-schema.js` (safe): No malicious patterns detected; the code is a legitimate JSON Schema generator with no network, filesystem, credential, or code-execution red flags.
- `v4/core/util.cjs` (safe): No malicious patterns detected; the only dynamic code execution is a benign feature-detection use of `new Function`.
- `v4/core/util.js` (safe): No malicious patterns detected; the code contains standard utility functions from Zod library with no security concerns.
- `v4/core/versions.cjs` (safe): No malicious patterns detected
- `v4/core/versions.js` (safe): Cleared by Jev triage; no further analysis needed
- `v4/index.cjs` (safe): No malicious patterns detected
- `v4/index.js` (safe): Cleared by Jev triage; no further analysis needed
- `v4/locales/ar.cjs` (safe): This file is a standard TypeScript-compiled localization module containing only Arabic translation strings and error message formatting utilities, with no malicious patterns detected.
- `v4/locales/ar.js` (safe): Cleared by Jev triage; no further analysis needed
- `v4/locales/az.cjs` (safe): This is a standard Zod library locale file for Azerbaijani translations containing only error message formatting logic with no malicious patterns.
- `v4/locales/az.js` (safe): Cleared by Jev triage; no further analysis needed
- `v4/locales/be.cjs` (safe): No malicious patterns detected; the file is a standard localization module for Belarusian error messages with no network, filesystem, process, or dynamic code execution activity.
- `v4/locales/be.js` (safe): Cleared by Jev triage; no further analysis needed
- `v4/locales/ca.cjs` (safe): No malicious patterns detected; the file is a standard localization module for validation error messages in Catalan with no network, filesystem, process, or dynamic code execution activity.
- `v4/locales/ca.js` (safe): Cleared by Jev triage; no further analysis needed
- `v4/locales/cs.cjs` (safe): No malicious patterns detected
- `v4/locales/cs.js` (safe): Cleared by Jev triage; no further analysis needed
- `v4/locales/de.cjs` (safe): No malicious patterns detected; this is a German locale translation file for the Zod validation library with only static error message strings and standard TypeScript helper functions.
- `v4/locales/de.js` (safe): Cleared by Jev triage; no further analysis needed
- `v4/locales/en.cjs` (safe): No malicious patterns detected
- `v4/locales/en.js` (safe): Cleared by Jev triage; no further analysis needed
- `v4/locales/eo.cjs` (safe): No malicious patterns detected
- `v4/locales/eo.js` (safe): Cleared by Jev triage; no further analysis needed
- `v4/locales/es.cjs` (safe): This file is a Spanish locale error message definition for a validation library, containing only static string tables and pure translation logic with no network, filesystem, process, or dynamic execution activity.
- `v4/locales/es.js` (safe): Cleared by Jev triage; no further analysis needed
- `v4/locales/fa.cjs` (safe): This file is a standard internationalization (i18n) locale definition for error messages in Persian; it contains no malicious patterns, network activity, file system access, or dynamic code execution.
- `v4/locales/fa.js` (safe): Cleared by Jev triage; no further analysis needed
- `v4/locales/fi.cjs` (safe): No malicious patterns detected; the file is a standard localization module for the Zod validation library containing only Finnish error message translations and harmless utility imports.
- `v4/locales/fi.js` (safe): Cleared by Jev triage; no further analysis needed
- `v4/locales/fr-CA.cjs` (safe): This is a standard TypeScript/CommonJS locale translation file for a validation library, containing only static error message strings and no malicious patterns.

## Version ranges

1 of 4 scanned versions of zod are flagged: 4.6.5 (critical). The latest scanned version, 4.6.5, is critical risk. Only versions we have scanned are listed; unscanned versions between them are not covered.

- 4.6.5 (`4.6.5`): critical (Dynamic code execution +4 more)
- 3.25.76 – 4.1.13 (`>=3.25.76 <=4.1.13`): medium (Dynamic code execution +2 more)
- 3.23.8 (`3.23.8`): not scanned
- 3.22.4 (`3.22.4`): clean
- Flagged file `v4/core/checks.cjs` (critical) present in 4.6.5
- Flagged file `v4/core/doc.cjs` (critical) present in 4.6.5; finding IDs `NPS-9534A8F558A8`, `NPS-22B097E9EAFF`, `NPS-ADAE75B39B3B`

## Scanned versions

- [4.6.5](https://security.togoder.click/npm/zod@4.6.5): critical, 2026-10-06T14:25:39.000Z
- [4.1.13](https://security.togoder.click/npm/zod@4.1.13): medium, 2026-10-04T16:54:46.000Z
- [3.25.76](https://security.togoder.click/npm/zod@3.25.76): medium, 2026-10-04T16:54:47.000Z
- [3.22.4](https://security.togoder.click/npm/zod@3.22.4): safe, 2026-10-04T16:54:43.000Z

AI analysis is guidance, not a guarantee. Methodology: https://security.togoder.click/methodology
