Togoder security

npm package security report

zod@4.1.13 security report

Risky patterns found that deserve a look.

Needs review Version 4.1.13 Files reviewed 298 Size 2.3 MB Scanned

Summary

Togoder Security scanned the npm package zod@4.1.13 on Oct 4, 2026. An AI review of 298 source files produced 1 high, 3 medium, 19 low severity findings. The overall verdict is medium: the findings flag risky but common patterns (dynamic code, unsafe defaults, broad file or network access) rather than confirmed malware.

0
critical
1
high
3
medium
19
low

Findings 23

high

Dynamic code execution

NPS-EB9A0FECE2ED

The compile() method retrieves the Function constructor indirectly via const F = Function; and invokes it via new F(...args, lines.join("\n")). This builds a new function from dynamically assembled source code (args and content), which is functionally equivalent to eval/new Function. If args or content can ever be influenced by untrusted input (e.g., user data, remote config, environment-derived strings), this becomes an arbitrary code execution sink. The indirect assignment is a mild obfuscation pattern that can evade naive static scanners looking only for the literal new Function(...).

v4/core/doc.cjs:36
medium

Dynamic code execution

NPS-73EEDEB528F1

The compile() method uses the Function constructor (new Function) to dynamically create and execute code from strings. This is a form of eval-equivalent dynamic code execution. While this appears to be a legitimate SQL query builder utility (likely drizzle-orm's doc builder), the pattern of constructing executable code from template strings and arbitrary args is inherently risky and could lead to code injection if user-controlled data ever reaches the content or args parameters.

src/v4/core/doc.ts:41
medium

Dynamic code execution

NPS-1E85D0FE4531

The compile() method uses the Function constructor to dynamically compile and execute arbitrary code from the args and content properties. This can lead to code injection if untrusted input reaches these fields, effectively behaving like eval.

v4/core/doc.js:33
medium

Dynamic code execution detection utility

NPS-5E2674B31DC0

The allowsEval function checks whether the Function constructor can be used (e.g., new F('')) to determine environment CSP restrictions, with a special case for Cloudflare user agents. While used here for feature detection rather than executing attacker-controlled code, it indicates the library may rely on dynamic code evaluation elsewhere, which is a code-execution primitive risk.

v4/core/util.cjs
low

top-level code execution on import

NPS-888F7E6CFC37

The module calls config(en()) at import time, which is a side-effectful global initialization. While this is legitimate zod locale configuration and not malicious, it is top-level code that runs when the module is imported.

src/v4/classic/external.ts:10
low

Type-level dynamic behavior

NPS-E7024C0AF0B9

The $replace conditional type recursively transforms metadata types at compile time. This is a legitimate TypeScript utility and not runtime code execution, but deep recursive conditional types on untrusted complex schemas could lead to excessive type instantiation / compiler resource exhaustion (a known DoS vector for type-heavy packages) when consumers pass adversarial types.

src/v4/core/registries.ts:11
low

Global state pollution

NPS-7B899F4C38E5

The module writes to globalThis.__zod_globalRegistry at import time, mutating shared global state. While the stated intent is deduplication across CJS/ESM builds, attaching named properties to globalThis can be abused by other code to hijack or overwrite the registry (e.g., registry poisoning or prototype pollution scenarios) and makes the module's behavior dependent on ambient global state.

src/v4/core/registries.ts:118
low

Top-level import-time code execution

NPS-926EF85F9F1E

The statement (globalThis as GlobalThisWithRegistry).__zod_globalRegistry ??= registry<GlobalMeta>(); runs at module import time, creating a shared mutable registry on the global object. Any code that imports this module will automatically trigger this side effect, which is a common pattern exploited in supply-chain attacks to persist state or install hooks.

src/v4/core/registries.ts:118
low

Dynamic code execution capability detection

NPS-9164CA0EB672

The allowsEval cached getter attempts new Function('') to probe whether dynamic code evaluation is allowed in the runtime, and returns false on Cloudflare Workers based on navigator.userAgent. This is a capability probe, not an exploit: it does not execute attacker-controlled input, and guards against environments where new Function would throw. It is a common pattern in validation libraries to decide whether to use eval-based fast paths. No payload, no exfiltration, no abuse.

src/v4/core/util.ts
low

Weak randomness in randomString

NPS-CC5A9AFE5D96

randomString uses Math.random() to generate identifiers. This is cryptographically insecure and could be a problem if the output is used as a token, nonce, or session identifier. In this library the function appears to be a generic utility (e.g., for generating test/schema IDs), and no secret material is derived from it in this file, but callers should avoid using it for security-sensitive values.

src/v4/core/util.ts
low

Use of atob/btoa and base64 conversion helpers

NPS-517B5A4E1913

The base64/hex conversion helpers use atob/btoa and manual byte array construction. These are standard encoding utilities, not obfuscation. No hidden payloads are present and no data is transmitted externally.

src/v4/core/util.ts
low

Dual sync/async execution of caller-supplied function

NPS-E949D5582ADD

In write(arg), if arg is a function it is invoked twice: once with { execution: "sync" } and once with { execution: "async" }. This pattern mirrors documented magicast/ast-types-style code generation usage, but invoking a callback twice with the same Doc instance and different flags is a control-flow oddity worth reviewing: a callback that mutates this.content non-idempotently can duplicate or corrupt generated code, and the async pass suggests execution paths not fully visible in this file.

v4/core/doc.cjs:18
low

dynamic_code_execution

NPS-AFBA2C5A0956

The file uses new Function/compile for JIT code generation in $ZodObjectJIT (Doc.compile). This is a legitimate optimization in Zod for object parsing. It does not use external/untrusted input to compile code; it generates code from schema shape keys after escaping them via util.esc. No eval, no process spawning, no network I/O.

v4/core/schemas.js
low

Insecure randomness

NPS-FC520033F63E

randomString uses Math.random() to generate strings. This is not cryptographically secure and may be inappropriate for security-sensitive contexts (e.g., token generation), though within zod it is likely only used for internal identifiers.

v4/core/util.cjs
low

Proxy/reflection utilities

NPS-739AF35A7615

createTransparentProxy and various Reflect.* operations allow unrestricted property interception, which could be misused if applied to security-sensitive objects, though by itself it is a normal library utility.

v4/core/util.cjs
low

Environment detection

NPS-1EE6306C44BC

The allowsEval getter inspects navigator.userAgent for Cloudflare; behavior differing by environment can be a fingerprinting/evasion pattern, though here it plausibly reflects CSP/workerd constraints.

v4/core/util.cjs
low

Prototype pollution potential

NPS-2E98581A0372

The assignProp and mergeDefs functions use Object.defineProperty and Object.assign with user-controlled keys (e.g., prop, descriptors from defs). While these are internal utilities, if exposed to untrusted input, they could allow modification of object prototypes or injection of malicious properties. However, in the context of schema definition (zod library), the inputs are typically developer-controlled.

v4/core/util.js:106
low

Insecure randomness

NPS-9BDA4C8DB81B

The randomString function uses Math.random(), which is not cryptographically secure. If this function is used for generating tokens, nonces, or other security-sensitive values, it could introduce predictability. It appears to be a utility for generating random strings, but the naming and general-purpose nature warrant caution.

v4/core/util.js:124
low

Global object access

NPS-FB89ADF97E0F

The captureStackTrace constant references Error.captureStackTrace, which is a V8-specific extension. This is not malicious but indicates environment-specific behavior. No security risk directly.

v4/core/util.js:133
low

Dynamic code execution capability

NPS-C78E75D32C71

The allowsEval function uses new Function('') to test whether dynamic code evaluation is allowed in the current environment. While this specific call does not execute attacker-controlled code, the presence of this capability check suggests the library may conditionally use eval/Function elsewhere, which is a code smell and potential risk if inputs are not properly sanitized.

v4/core/util.js:142
low

Potential information disclosure via errors

NPS-F0FC3CA07A0F

The finalizeIssue function constructs error messages and deletes certain fields (inst, continue, input). If not properly configured, error messages might include sensitive input data. However, there is logic to delete input unless ctx?.reportInput is true, which is a reasonable safeguard.

v4/core/util.js:361
low

Use of `atob`/`btoa`

NPS-C98FB4600478

The base64 encoding/decoding functions use atob and btoa, which are standard in browsers and Node.js. No obfuscation or malicious payload is detected. However, these functions are often used in encoded payloads; here they appear to be legitimate codec utilities.

v4/core/util.js:392
low

Deprecated alias

NPS-7FBA43DB92FE

This file only re-exports the Ukrainian locale from './uk.cjs' and marks the previous 'ua' locale as deprecated. It contains no suspicious imports, network calls, environment access, dynamic execution, or process spawning.

v4/locales/ua.cjs

Files reviewed

FileVerdictWhat the reviewer saw
src/v4/core/doc.ts medium Contains a Function constructor-based dynamic code execution pattern in compile(), which is a code-injection risk if untrusted input reaches its arguments, though no overt malicious behavior was found.
src/v4/core/registries.ts medium No data exfiltration, credential harvesting, obfuscation, or malicious execution was found; the only concerns are the import-time mutation of globalThis and heavy recursive type utilities, which warrant a warning but not a critical rating.
v4/core/doc.cjs medium File contains dynamic function construction via the Function constructor with assembled source and an unusual dual sync/async callback invocation, but no network, filesystem, environment harvesting, or process-spawning behavior was observed.
v4/core/doc.js medium The file uses dynamic code generation via the Function constructor, which is a potential code injection risk, but no other malicious patterns were detected.
v4/core/util.cjs medium The file is a standard zod utility module with no network, filesystem, process, or exfiltration activity, but contains Function-based eval detection and non-cryptographic randomness worth noting.
v4/core/util.js medium The file contains utility functions for a schema validation library (likely zod) with no clear malicious intent; a few low-severity code smells such as the use of new Function for capability detection and Math.random for string generation were noted, but no data exfiltration, backdoors, or process spawning were detected.
index.cjs safe No malicious patterns detected; the code is standard TypeScript/CommonJS interop boilerplate re-exporting from a local module.
index.js safe Cleared by Jev triage; no further analysis needed
locales/index.cjs safe No malicious patterns detected; the file only re-exports locale definitions using standard TypeScript helper functions.
locales/index.js safe Cleared by Jev triage; no further analysis needed
mini/index.cjs safe No malicious patterns detected; the file is a standard TypeScript-generated CommonJS re-export shim.
mini/index.js safe Cleared by Jev triage; no further analysis needed
src/index.ts safe Cleared by Jev triage; no further analysis needed
src/locales/index.ts safe Cleared by Jev triage; no further analysis needed
src/mini/index.ts safe Cleared by Jev triage; no further analysis needed
src/v3/ZodError.ts safe Cleared by Jev triage; no further analysis needed
src/v3/benchmarks/datetime.ts safe Cleared by Jev triage; no further analysis needed
src/v3/benchmarks/discriminatedUnion.ts safe Cleared by Jev triage; no further analysis needed
src/v3/benchmarks/index.ts safe No malicious patterns detected; the file is a standard benchmark runner that reads CLI arguments and runs in-memory benchmarks without network, filesystem, or process-spawning operations.
src/v3/benchmarks/ipv4.ts safe Cleared by Jev triage; no further analysis needed
src/v3/benchmarks/object.ts safe Cleared by Jev triage; no further analysis needed
src/v3/benchmarks/primitives.ts safe Cleared by Jev triage; no further analysis needed
src/v3/benchmarks/realworld.ts safe No malicious patterns detected; the code is a standard Zod validation benchmark with no network, filesystem, process, or obfuscated behavior.
src/v3/benchmarks/string.ts safe Cleared by Jev triage; no further analysis needed
src/v3/benchmarks/union.ts safe Cleared by Jev triage; no further analysis needed
Show 273 more files
FileVerdictWhat the reviewer saw
src/v3/errors.ts safe Cleared by Jev triage; no further analysis needed
src/v3/external.ts safe Cleared by Jev triage; no further analysis needed
src/v3/helpers/enumUtil.ts safe Cleared by Jev triage; no further analysis needed
src/v3/helpers/errorUtil.ts safe Cleared by Jev triage; no further analysis needed
src/v3/helpers/parseUtil.ts safe Cleared by Jev triage; no further analysis needed
src/v3/helpers/partialUtil.ts safe Cleared by Jev triage; no further analysis needed
src/v3/helpers/typeAliases.ts safe Cleared by Jev triage; no further analysis needed
src/v3/helpers/util.ts safe Cleared by Jev triage; no further analysis needed
src/v3/index.ts safe Cleared by Jev triage; no further analysis needed
src/v3/locales/en.ts safe Cleared by Jev triage; no further analysis needed
src/v3/standard-schema.ts safe Cleared by Jev triage; no further analysis needed
src/v4-mini/index.ts safe Cleared by Jev triage; no further analysis needed
src/v4/classic/checks.ts safe Cleared by Jev triage; no further analysis needed
src/v4/classic/coerce.ts safe Cleared by Jev triage; no further analysis needed
src/v4/classic/compat.ts safe Cleared by Jev triage; no further analysis needed
src/v4/classic/errors.ts safe Cleared by Jev triage; no further analysis needed
src/v4/classic/external.ts safe This is a legitimate zod re-export module with only a benign top-level locale initialization side effect; no malicious patterns detected.
src/v4/classic/index.ts safe Cleared by Jev triage; no further analysis needed
src/v4/classic/iso.ts safe Cleared by Jev triage; no further analysis needed
src/v4/classic/parse.ts safe Cleared by Jev triage; no further analysis needed
src/v4/classic/schemas.ts safe Cleared by Jev triage; no further analysis needed
src/v4/core/api.ts safe Cleared by Jev triage; no further analysis needed
src/v4/core/checks.ts safe This is the Zod validation library's check definitions; it contains no network calls, dynamic execution, credential access, or other malicious patterns.
src/v4/core/config.ts safe Cleared by Jev triage; no further analysis needed
src/v4/core/core.ts safe No malicious patterns detected; the file contains only Zod core constructor utilities and type helpers with no network, filesystem, process, or dynamic execution behavior.
src/v4/core/errors.ts safe Cleared by Jev triage; no further analysis needed
src/v4/core/index.ts safe Cleared by Jev triage; no further analysis needed
src/v4/core/json-schema.ts safe Cleared by Jev triage; no further analysis needed
src/v4/core/parse.ts safe Cleared by Jev triage; no further analysis needed
src/v4/core/regexes.ts safe This file contains only regular expression definitions for validation purposes and imports a local utility module; no malicious patterns, dynamic code execution, network activity, or obfuscation were detected.
src/v4/core/standard-schema.ts safe Cleared by Jev triage; no further analysis needed
src/v4/core/to-json-schema.ts safe Legitimate Zod library JSON Schema conversion code with no malicious patterns detected.
src/v4/core/util.ts safe The file is a collection of type definitions and utility helpers for a schema validation library (Zod v4); no malicious patterns such as exfiltration, credential harvesting, backdoors, process spawning, or encoded payloads were detected, only a benign new Function capability probe and a cryptographically weak random string helper.
src/v4/core/versions.ts safe Cleared by Jev triage; no further analysis needed
src/v4/core/zsf.ts safe Cleared by Jev triage; no further analysis needed
src/v4/index.ts safe Cleared by Jev triage; no further analysis needed
src/v4/locales/ar.ts safe Cleared by Jev triage; no further analysis needed
src/v4/locales/az.ts safe Cleared by Jev triage; no further analysis needed
src/v4/locales/be.ts safe Cleared by Jev triage; no further analysis needed
src/v4/locales/bg.ts safe Cleared by Jev triage; no further analysis needed
src/v4/locales/ca.ts safe Cleared by Jev triage; no further analysis needed
src/v4/locales/cs.ts safe Cleared by Jev triage; no further analysis needed
src/v4/locales/da.ts safe Cleared by Jev triage; no further analysis needed
src/v4/locales/de.ts safe Cleared by Jev triage; no further analysis needed
src/v4/locales/en.ts safe Cleared by Jev triage; no further analysis needed
src/v4/locales/eo.ts safe Cleared by Jev triage; no further analysis needed
src/v4/locales/es.ts safe Cleared by Jev triage; no further analysis needed
src/v4/locales/fa.ts safe Cleared by Jev triage; no further analysis needed
src/v4/locales/fi.ts safe Cleared by Jev triage; no further analysis needed
src/v4/locales/fr-CA.ts safe Cleared by Jev triage; no further analysis needed
src/v4/locales/fr.ts safe Cleared by Jev triage; no further analysis needed
src/v4/locales/he.ts safe Cleared by Jev triage; no further analysis needed
src/v4/locales/hu.ts safe Cleared by Jev triage; no further analysis needed
src/v4/locales/id.ts safe Cleared by Jev triage; no further analysis needed
src/v4/locales/index.ts safe Cleared by Jev triage; no further analysis needed
src/v4/locales/is.ts safe Cleared by Jev triage; no further analysis needed
src/v4/locales/it.ts safe Cleared by Jev triage; no further analysis needed
src/v4/locales/ja.ts safe Cleared by Jev triage; no further analysis needed
src/v4/locales/ka.ts safe Cleared by Jev triage; no further analysis needed
src/v4/locales/kh.ts safe Cleared by Jev triage; no further analysis needed
src/v4/locales/km.ts safe Cleared by Jev triage; no further analysis needed
src/v4/locales/ko.ts safe Cleared by Jev triage; no further analysis needed
src/v4/locales/lt.ts safe Cleared by Jev triage; no further analysis needed
src/v4/locales/mk.ts safe Cleared by Jev triage; no further analysis needed
src/v4/locales/ms.ts safe Cleared by Jev triage; no further analysis needed
src/v4/locales/nl.ts safe Cleared by Jev triage; no further analysis needed
src/v4/locales/no.ts safe Cleared by Jev triage; no further analysis needed
src/v4/locales/ota.ts safe Cleared by Jev triage; no further analysis needed
src/v4/locales/pl.ts safe Cleared by Jev triage; no further analysis needed
src/v4/locales/ps.ts safe Cleared by Jev triage; no further analysis needed
src/v4/locales/pt.ts safe Cleared by Jev triage; no further analysis needed
src/v4/locales/ru.ts safe Cleared by Jev triage; no further analysis needed
src/v4/locales/sl.ts safe Cleared by Jev triage; no further analysis needed
src/v4/locales/sv.ts safe Cleared by Jev triage; no further analysis needed
src/v4/locales/ta.ts safe Cleared by Jev triage; no further analysis needed
src/v4/locales/th.ts safe Cleared by Jev triage; no further analysis needed
src/v4/locales/tr.ts safe Cleared by Jev triage; no further analysis needed
src/v4/locales/ua.ts safe Cleared by Jev triage; no further analysis needed
src/v4/locales/uk.ts safe Cleared by Jev triage; no further analysis needed
src/v4/locales/ur.ts safe Cleared by Jev triage; no further analysis needed
src/v4/locales/vi.ts safe Cleared by Jev triage; no further analysis needed
src/v4/locales/yo.ts safe Cleared by Jev triage; no further analysis needed
src/v4/locales/zh-CN.ts safe Cleared by Jev triage; no further analysis needed
src/v4/locales/zh-TW.ts safe Cleared by Jev triage; no further analysis needed
src/v4/mini/checks.ts safe Cleared by Jev triage; no further analysis needed
src/v4/mini/coerce.ts safe Cleared by Jev triage; no further analysis needed
src/v4/mini/external.ts safe Cleared by Jev triage; no further analysis needed
src/v4/mini/index.ts safe Cleared by Jev triage; no further analysis needed
src/v4/mini/iso.ts safe Cleared by Jev triage; no further analysis needed
src/v4/mini/parse.ts safe Cleared by Jev triage; no further analysis needed
src/v4/mini/schemas.ts safe Cleared by Jev triage; no further analysis needed
v3/ZodError.cjs safe Cleared by Jev triage; no further analysis needed
v3/ZodError.js safe Cleared by Jev triage; no further analysis needed
v3/errors.cjs safe No malicious patterns detected; the file only manages error message localization maps without network, filesystem, or process operations.
v3/errors.js safe Cleared by Jev triage; no further analysis needed
v3/external.cjs safe No malicious patterns detected; this file only contains standard TypeScript CommonJS re-export boilerplate.
v3/external.js safe Cleared by Jev triage; no further analysis needed
v3/helpers/enumUtil.cjs safe No malicious patterns detected
v3/helpers/enumUtil.js safe Cleared by Jev triage; no further analysis needed
v3/helpers/errorUtil.cjs safe No malicious patterns detected
v3/helpers/errorUtil.js safe No malicious patterns detected; the code is a simple utility for converting error messages to objects or strings.
v3/helpers/parseUtil.cjs safe No malicious patterns detected; the file contains only standard validation and error-handling utilities from a Zod-like library.
v3/helpers/parseUtil.js safe Cleared by Jev triage; no further analysis needed
v3/helpers/partialUtil.cjs safe No malicious patterns detected
v3/helpers/partialUtil.js safe Cleared by Jev triage; no further analysis needed
v3/helpers/typeAliases.cjs safe No malicious patterns detected
v3/helpers/typeAliases.js safe Cleared by Jev triage; no further analysis needed
v3/helpers/util.cjs safe The code is a utility module for the Zod validation library and contains no malicious patterns, network calls, file system access, or dynamic code execution.
v3/helpers/util.js safe No malicious patterns detected
v3/index.cjs safe No malicious patterns detected
v3/index.js safe Cleared by Jev triage; no further analysis needed
v3/locales/en.cjs safe Cleared by Jev triage; no further analysis needed
v3/locales/en.js safe Cleared by Jev triage; no further analysis needed
v3/standard-schema.cjs safe No malicious patterns detected
v3/standard-schema.js safe Cleared by Jev triage; no further analysis needed
v4-mini/index.cjs safe No malicious patterns detected; the file is a standard TypeScript-generated CommonJS re-export shim.
v4-mini/index.js safe Cleared by Jev triage; no further analysis needed
v4/classic/checks.cjs safe No malicious patterns detected; the file is a straightforward re-export module for Zod validation checks.
v4/classic/checks.js safe Cleared by Jev triage; no further analysis needed
v4/classic/coerce.cjs safe No malicious patterns detected; the code is standard TypeScript-compiled helper functions for Zod schema coercion with no suspicious behavior.
v4/classic/coerce.js safe Cleared by Jev triage; no further analysis needed
v4/classic/compat.cjs safe This is a standard Zod v3 compatibility shim using TypeScript's commonjs interop helpers to re-export core modules and deprecated APIs; no malicious patterns detected.
v4/classic/compat.js safe Cleared by Jev triage; no further analysis needed
v4/classic/errors.cjs safe No malicious patterns detected
v4/classic/errors.js safe Cleared by Jev triage; no further analysis needed
v4/classic/external.cjs safe No malicious patterns detected; the code is standard TypeScript/CommonJS module boilerplate and re-exports for the Zod library.
v4/classic/external.js safe No malicious patterns detected
v4/classic/index.cjs safe No malicious patterns detected
v4/classic/index.js safe Cleared by Jev triage; no further analysis needed
v4/classic/iso.cjs safe No malicious patterns detected; the code is a standard TypeScript-compiled Zod library module for ISO date/time schemas with only benign module import/export logic.
v4/classic/iso.js safe No malicious patterns detected
v4/classic/parse.cjs safe No malicious patterns detected; the file contains standard TypeScript/CommonJS interop helpers and re-exports of Zod validation functions.
v4/classic/parse.js safe Cleared by Jev triage; no further analysis needed
v4/classic/schemas.cjs safe No malicious patterns detected
v4/classic/schemas.js safe No malicious patterns detected; this is legitimate Zod schema definition code with no exfiltration, dynamic execution, network, or process-spawning behavior.
v4/core/api.cjs safe No malicious patterns detected
v4/core/api.js safe No malicious patterns detected; this is legitimate Zod validation library code with no data exfiltration, credential harvesting, obfuscation, process spawning, or other suspicious behavior.
v4/core/checks.cjs safe No malicious patterns detected; the code is a standard Zod validation library module with no exfiltration, credential harvesting, obfuscation, or dynamic code execution.
v4/core/checks.js safe No malicious patterns detected in this Zod validation checks module; it only contains schema validation logic with no network, filesystem, process, or dynamic code execution activity.
v4/core/core.cjs safe No malicious patterns detected; the code is a legitimate utility module from the Zod validation library with no network, filesystem, process execution, or obfuscated behavior.
v4/core/core.js safe No malicious patterns detected
v4/core/errors.cjs safe No malicious patterns detected; the file is a standard TypeScript-compiled Zod error formatting utility with no network, filesystem, process, or dynamic execution behavior.
v4/core/errors.js safe Cleared by Jev triage; no further analysis needed
v4/core/index.cjs safe No malicious patterns detected; the file contains standard TypeScript/CommonJS module re-export boilerplate.
v4/core/index.js safe Cleared by Jev triage; no further analysis needed
v4/core/json-schema.cjs safe No malicious patterns detected
v4/core/json-schema.js safe Cleared by Jev triage; no further analysis needed
v4/core/parse.cjs safe This is a legitimate Zod validation library file with standard TypeScript helper functions and parsing logic, containing no malicious patterns.
v4/core/parse.js safe No malicious patterns detected
v4/core/regexes.cjs safe No malicious patterns detected; the file contains only regex definitions for common validation patterns and helper functions with no external I/O, dynamic code execution, or suspicious behavior.
v4/core/regexes.js safe No malicious patterns detected
v4/core/registries.cjs safe No malicious patterns detected; the code implements a schema registry with WeakMap/Map storage and standard Zod symbol exports.
v4/core/registries.js safe No malicious patterns detected; the code implements a benign schema metadata registry using WeakMap/Map with no network, filesystem, process execution, or obfuscated code.
v4/core/schemas.cjs safe No malicious patterns detected; this is a legitimate Zod schema validation library file with no data exfiltration, dynamic code execution, or credential harvesting.
v4/core/schemas.js safe Zod schema implementation contains only legitimate validation logic; dynamic code generation is confined to internal JIT compilation of schema shapes without external input or malicious behavior.
v4/core/standard-schema.cjs safe No malicious patterns detected
v4/core/standard-schema.js safe Cleared by Jev triage; no further analysis needed
v4/core/to-json-schema.cjs safe No malicious patterns detected; the code is a standard JSON Schema generator from Zod with no network, filesystem, credential, or dynamic execution activity.
v4/core/to-json-schema.js safe No malicious patterns detected; the code is a legitimate JSON Schema generator for Zod with no network, filesystem, process, or dynamic code execution activities.
v4/core/versions.cjs safe No malicious patterns detected
v4/core/versions.js safe Cleared by Jev triage; no further analysis needed
v4/index.cjs safe No malicious patterns detected
v4/index.js safe Cleared by Jev triage; no further analysis needed
v4/locales/ar.cjs safe No malicious patterns detected
v4/locales/ar.js safe Cleared by Jev triage; no further analysis needed
v4/locales/az.cjs safe No malicious patterns detected; the file is a standard localization module for Zod validation errors in Azerbaijani.
v4/locales/az.js safe Cleared by Jev triage; no further analysis needed
v4/locales/be.cjs safe No malicious patterns detected
v4/locales/be.js safe Cleared by Jev triage; no further analysis needed
v4/locales/bg.cjs safe No malicious patterns detected; this is a standard localization/error message file for a validation library with no network, filesystem, process, or dynamic code execution activity.
v4/locales/bg.js safe Cleared by Jev triage; no further analysis needed
v4/locales/ca.cjs safe No malicious patterns detected
v4/locales/ca.js safe Cleared by Jev triage; no further analysis needed
v4/locales/cs.cjs safe No malicious patterns detected
v4/locales/cs.js safe Cleared by Jev triage; no further analysis needed
v4/locales/da.cjs safe This is a standard Zod locale file containing Danish translations for validation error messages, with no malicious patterns or security concerns.
v4/locales/da.js safe Cleared by Jev triage; no further analysis needed
v4/locales/de.cjs safe This is a German localization file for a validation library with no malicious patterns, network activity, or code execution beyond standard TypeScript helper functions.
v4/locales/de.js safe Cleared by Jev triage; no further analysis needed
v4/locales/en.cjs safe No malicious patterns detected
v4/locales/en.js safe Cleared by Jev triage; no further analysis needed
v4/locales/eo.cjs safe No malicious patterns detected
v4/locales/eo.js safe Cleared by Jev triage; no further analysis needed
v4/locales/es.cjs safe No malicious patterns detected; the file is a locale/error message module for the Zod validation library (Spanish translations) and only imports a local utility module.
v4/locales/es.js safe Cleared by Jev triage; no further analysis needed
v4/locales/fa.cjs safe No malicious patterns detected; the file is a standard localization module for Zod validation error messages in Persian.
v4/locales/fa.js safe Cleared by Jev triage; no further analysis needed
v4/locales/fi.cjs safe This is a standard Finnish locale file for a validation library (likely zod), containing only error message translations and no malicious patterns.
v4/locales/fi.js safe Cleared by Jev triage; no further analysis needed
v4/locales/fr-CA.cjs safe No malicious patterns detected; the file is a benign localization module with only string definitions and no network, filesystem, process, or dynamic execution behavior.
v4/locales/fr-CA.js safe Cleared by Jev triage; no further analysis needed
v4/locales/fr.cjs safe No malicious patterns detected
v4/locales/fr.js safe Cleared by Jev triage; no further analysis needed
v4/locales/he.cjs safe No malicious patterns detected; this is a legitimate Hebrew locale/error message file for a validation library.
v4/locales/he.js safe Cleared by Jev triage; no further analysis needed
v4/locales/hu.cjs safe No malicious patterns detected
v4/locales/hu.js safe Cleared by Jev triage; no further analysis needed
v4/locales/id.cjs safe No malicious patterns detected; the file is a standard localization module for Indonesian error messages with only import-time module setup and no network, file system, process, or dynamic code execution.
v4/locales/id.js safe Cleared by Jev triage; no further analysis needed
v4/locales/index.cjs safe No malicious patterns detected; the file is a standard locale index that statically re-exports locale modules using CommonJS getters.
v4/locales/index.js safe Cleared by Jev triage; no further analysis needed
v4/locales/is.cjs safe No malicious patterns detected; the code is a standard localization module with no network, filesystem, or dynamic execution behavior.
v4/locales/is.js safe Cleared by Jev triage; no further analysis needed
v4/locales/it.cjs safe No malicious patterns detected; the file contains only legitimate Italian localization strings for error messages.
v4/locales/it.js safe Cleared by Jev triage; no further analysis needed
v4/locales/ja.cjs safe No malicious patterns detected; this is a standard localization file for the Japanese locale of the zod validation library.
v4/locales/ja.js safe Cleared by Jev triage; no further analysis needed
v4/locales/ka.cjs safe No malicious patterns detected; this is a standard localization file containing Georgian error messages with no network, file system, process, or dynamic execution behavior.
v4/locales/ka.js safe Cleared by Jev triage; no further analysis needed
v4/locales/kh.cjs safe No malicious patterns detected; this is a simple deprecated locale alias that re-exports the 'km' locale with no external calls or dynamic execution.
v4/locales/kh.js safe Cleared by Jev triage; no further analysis needed
v4/locales/km.cjs safe This is a Zod library locale file for Khmer (km) error messages, containing only translation strings and standard TypeScript helper functions with no malicious patterns.
v4/locales/km.js safe Cleared by Jev triage; no further analysis needed
v4/locales/ko.cjs safe No malicious patterns detected; the file is a standard locale translation module for the Zod validation library.
v4/locales/ko.js safe Cleared by Jev triage; no further analysis needed
v4/locales/lt.cjs safe No malicious patterns detected
v4/locales/lt.js safe Cleared by Jev triage; no further analysis needed
v4/locales/mk.cjs safe No malicious patterns detected; the file is a standard localization module for the Zod validation library with only TypeScript interop boilerplate and static error message strings.
v4/locales/mk.js safe Cleared by Jev triage; no further analysis needed
v4/locales/ms.cjs safe This file is a legitimate localized error message module for the Zod validation library, containing only static string translations and no malicious patterns.
v4/locales/ms.js safe Cleared by Jev triage; no further analysis needed
v4/locales/nl.cjs safe No malicious patterns detected; the file is a standard Zod locale definition for Dutch error messages.
v4/locales/nl.js safe Cleared by Jev triage; no further analysis needed
v4/locales/no.cjs safe No malicious patterns detected; the file is a standard localization module with no network, filesystem, or dynamic code execution activity
v4/locales/no.js safe Cleared by Jev triage; no further analysis needed
v4/locales/ota.cjs safe This is a locale translation file for a validation library (likely Zod) with no malicious patterns, network activity, or code execution.
v4/locales/ota.js safe Cleared by Jev triage; no further analysis needed
v4/locales/pl.cjs safe This is a standard localization module for error messages with no malicious patterns detected.
v4/locales/pl.js safe Cleared by Jev triage; no further analysis needed
v4/locales/ps.cjs safe This is a Pashto locale file for the zod validation library containing only translation strings and error message formatting logic with no malicious patterns.
v4/locales/ps.js safe Cleared by Jev triage; no further analysis needed
v4/locales/pt.cjs safe No malicious patterns detected; the file is a legitimate Portuguese localization module for validation error messages with no network, filesystem, process, or dynamic code execution behavior.
v4/locales/pt.js safe Cleared by Jev triage; no further analysis needed
v4/locales/ru.cjs safe No malicious patterns detected
v4/locales/ru.js safe Cleared by Jev triage; no further analysis needed
v4/locales/sl.cjs safe No malicious patterns detected; the file is a standard localization module for validation error messages in Slovenian.
v4/locales/sl.js safe Cleared by Jev triage; no further analysis needed
v4/locales/sv.cjs safe No malicious patterns detected; the file is a standard Swedish locale definition for Zod validation errors with no network, filesystem, process, or dynamic code execution activity.
v4/locales/sv.js safe Cleared by Jev triage; no further analysis needed
v4/locales/ta.cjs safe No malicious patterns detected; the file only contains TypeScript-to-CommonJS helper functions and Tamil locale error messages.
v4/locales/ta.js safe Cleared by Jev triage; no further analysis needed
v4/locales/th.cjs safe No malicious patterns detected
v4/locales/th.js safe Cleared by Jev triage; no further analysis needed
v4/locales/tr.cjs safe No malicious patterns detected
v4/locales/tr.js safe Cleared by Jev triage; no further analysis needed
v4/locales/ua.cjs safe No malicious patterns detected; the code is a simple deprecated alias to the Ukrainian locale module.
v4/locales/ua.js safe Cleared by Jev triage; no further analysis needed
v4/locales/uk.cjs safe No malicious patterns detected; this is a legitimate Zod locale file with only localization strings and no network, filesystem, or command execution behavior.
v4/locales/uk.js safe Cleared by Jev triage; no further analysis needed
v4/locales/ur.cjs safe No malicious patterns detected
v4/locales/ur.js safe Cleared by Jev triage; no further analysis needed
v4/locales/vi.cjs safe No malicious patterns detected; the file contains only TypeScript-to-CommonJS helper boilerplate and Vietnamese localization error messages for a validation library.
v4/locales/vi.js safe Cleared by Jev triage; no further analysis needed
v4/locales/yo.cjs safe This is a standard Zod locale file for Yoruba translations containing only static translation strings and error formatting logic with no malicious patterns.
v4/locales/yo.js safe Cleared by Jev triage; no further analysis needed
v4/locales/zh-CN.cjs safe No malicious patterns detected; the code is a standard localization file for a validation library.
v4/locales/zh-CN.js safe Cleared by Jev triage; no further analysis needed
v4/locales/zh-TW.cjs safe No malicious patterns detected
v4/locales/zh-TW.js safe Cleared by Jev triage; no further analysis needed
v4/mini/checks.cjs safe No malicious patterns detected; the file only re-exports validator functions from the core module via safe property getters.
v4/mini/checks.js safe No malicious patterns detected; the file only re-exports validation functions from the core module.
v4/mini/coerce.cjs safe The file contains only standard TypeScript-to-CommonJS helpers and Zod schema coercion exports with no malicious patterns.
v4/mini/coerce.js safe Cleared by Jev triage; no further analysis needed
v4/mini/external.cjs safe No malicious patterns detected; the file contains only standard TypeScript-generated CommonJS module export boilerplate for the Zod library.
v4/mini/external.js safe Cleared by Jev triage; no further analysis needed
v4/mini/index.cjs safe The code is a standard TypeScript/CommonJS module re-export helper with no malicious patterns, external calls, or runtime execution beyond normal module loading.
v4/mini/index.js safe Cleared by Jev triage; no further analysis needed
v4/mini/iso.cjs safe No malicious patterns detected; the file contains standard TypeScript-to-CommonJS helper boilerplate and Zod schema definitions with no network, filesystem, process, or dynamic code execution behavior.
v4/mini/iso.js safe No malicious patterns detected
v4/mini/parse.cjs safe This file only re-exports functions from the core index module using standard CommonJS patterns, with no malicious behavior detected.
v4/mini/parse.js safe Cleared by Jev triage; no further analysis needed
v4/mini/schemas.cjs safe This is a legitimate Zod schema validation library file with no malicious patterns detected.
v4/mini/schemas.js safe No malicious patterns detected in this Zod schema definition file; it only contains schema type constructors and validation utilities.

Affected version ranges

1 of 4 scanned versions of zod are flagged: 4.6.5 (critical). The latest scanned version, 4.6.5, is critical risk. Only versions we have scanned are listed; unscanned versions between them are not covered.

3.22.44.6.5
VersionsVerdictCountRangeTop findings
4.6.5 Critical 1 4.6.5 Dynamic code execution; Dynamic code execution via new Function
3.25.76 โ€“ 4.1.13 Needs review 2 >=3.25.76 <=4.1.13 Dynamic code execution; Dynamic code execution via Function constructor
3.23.8 Not scanned 1 3.23.8
3.22.4 No issues 1 3.22.4

Flagged files across versions

  • critical v4/core/checks.cjs: present in 4.6.5
  • critical v4/core/doc.cjs (Dynamic code execution) NPS-9534A8F558A8: present in 4.6.5

Full list, including published versions not scanned yet: version ranges API.

Scanned versions of zod

VersionVerdictFilesScanned
4.6.5 Critical risk 375 Oct 6, 2026
4.1.13 Needs review 298 Oct 4, 2026
3.25.76 Needs review 271 Oct 4, 2026
3.22.4 No issues 18 Oct 4, 2026

Frequently asked questions

Is zod safe to use?

No confirmed malware was found in zod@4.1.13, but the review flagged 1 high, 3 medium, 19 low severity findings for risky patterns worth checking before you rely on it.

Does zod contain malware?

No malware was identified in zod@4.1.13 when Togoder Security scanned it on Oct 4, 2026. A new version can still introduce malicious code, so scan the exact versions in your lockfile.

How was zod checked?

Togoder Security downloaded the published npm package and had an AI model read its 298 source files, looking for install scripts, credential access, network exfiltration, obfuscation, backdoors and crypto-wallet theft. The results are cached by file hash and shown here.

How do I scan zod together with the rest of my dependencies?

Upload your lockfile at https://security.togoder.click/scan or call the API documented at https://security.togoder.click/api-docs. Files that have already been scanned, like the ones in zod@4.1.13, cost nothing.

Related security reports