# zod@4.1.13 security report (npm)

- Verdict: **Needs review** (risk level: medium)
- Scanned: 2026-10-04T16:54:46.000Z
- Files reviewed: 298
- Findings: 1 high, 3 medium, 19 low severity findings
- Report: https://security.togoder.click/npm/zod@4.1.13
- Source: Togoder Security (https://security.togoder.click), AI source-code review

## Summary

Togoder Security scanned the npm package zod@4.1.13 on Oct 4, 2026. An AI review of 298 source files produced 1 high, 3 medium, 19 low severity findings. The overall verdict is medium: the findings flag risky but common patterns (dynamic code, unsafe defaults, broad file or network access) rather than confirmed malware.

## Findings

### [high] Dynamic code execution

Finding ID: `NPS-EB9A0FECE2ED`

File: `v4/core/doc.cjs:36`

The `compile()` method retrieves the `Function` constructor indirectly via `const F = Function;` and invokes it via `new F(...args, lines.join("\n"))`. This builds a new function from dynamically assembled source code (`args` and `content`), which is functionally equivalent to `eval`/`new Function`. If `args` or `content` can ever be influenced by untrusted input (e.g., user data, remote config, environment-derived strings), this becomes an arbitrary code execution sink. The indirect assignment is a mild obfuscation pattern that can evade naive static scanners looking only for the literal `new Function(...)`.

### [medium] Dynamic code execution

Finding ID: `NPS-73EEDEB528F1`

File: `src/v4/core/doc.ts:41`

The compile() method uses the Function constructor (new Function) to dynamically create and execute code from strings. This is a form of eval-equivalent dynamic code execution. While this appears to be a legitimate SQL query builder utility (likely drizzle-orm's doc builder), the pattern of constructing executable code from template strings and arbitrary args is inherently risky and could lead to code injection if user-controlled data ever reaches the content or args parameters.

### [medium] Dynamic code execution

Finding ID: `NPS-1E85D0FE4531`

File: `v4/core/doc.js:33`

The `compile()` method uses the `Function` constructor to dynamically compile and execute arbitrary code from the `args` and `content` properties. This can lead to code injection if untrusted input reaches these fields, effectively behaving like `eval`.

### [medium] Dynamic code execution detection utility

Finding ID: `NPS-5E2674B31DC0`

File: `v4/core/util.cjs`

The `allowsEval` function checks whether the `Function` constructor can be used (e.g., `new F('')`) to determine environment CSP restrictions, with a special case for Cloudflare user agents. While used here for feature detection rather than executing attacker-controlled code, it indicates the library may rely on dynamic code evaluation elsewhere, which is a code-execution primitive risk.

### [low] top-level code execution on import

Finding ID: `NPS-888F7E6CFC37`

File: `src/v4/classic/external.ts:10`

The module calls config(en()) at import time, which is a side-effectful global initialization. While this is legitimate zod locale configuration and not malicious, it is top-level code that runs when the module is imported.

### [low] Type-level dynamic behavior

Finding ID: `NPS-E7024C0AF0B9`

File: `src/v4/core/registries.ts:11`

The $replace conditional type recursively transforms metadata types at compile time. This is a legitimate TypeScript utility and not runtime code execution, but deep recursive conditional types on untrusted complex schemas could lead to excessive type instantiation / compiler resource exhaustion (a known DoS vector for type-heavy packages) when consumers pass adversarial types.

### [low] Global state pollution

Finding ID: `NPS-7B899F4C38E5`

File: `src/v4/core/registries.ts:118`

The module writes to globalThis.__zod_globalRegistry at import time, mutating shared global state. While the stated intent is deduplication across CJS/ESM builds, attaching named properties to globalThis can be abused by other code to hijack or overwrite the registry (e.g., registry poisoning or prototype pollution scenarios) and makes the module's behavior dependent on ambient global state.

### [low] Top-level import-time code execution

Finding ID: `NPS-926EF85F9F1E`

File: `src/v4/core/registries.ts:118`

The statement `(globalThis as GlobalThisWithRegistry).__zod_globalRegistry ??= registry<GlobalMeta>();` runs at module import time, creating a shared mutable registry on the global object. Any code that imports this module will automatically trigger this side effect, which is a common pattern exploited in supply-chain attacks to persist state or install hooks.

### [low] Dynamic code execution capability detection

Finding ID: `NPS-9164CA0EB672`

File: `src/v4/core/util.ts`

The `allowsEval` cached getter attempts `new Function('')` to probe whether dynamic code evaluation is allowed in the runtime, and returns false on Cloudflare Workers based on navigator.userAgent. This is a capability probe, not an exploit: it does not execute attacker-controlled input, and guards against environments where `new Function` would throw. It is a common pattern in validation libraries to decide whether to use eval-based fast paths. No payload, no exfiltration, no abuse.

### [low] Weak randomness in randomString

Finding ID: `NPS-CC5A9AFE5D96`

File: `src/v4/core/util.ts`

`randomString` uses `Math.random()` to generate identifiers. This is cryptographically insecure and could be a problem if the output is used as a token, nonce, or session identifier. In this library the function appears to be a generic utility (e.g., for generating test/schema IDs), and no secret material is derived from it in this file, but callers should avoid using it for security-sensitive values.

### [low] Use of atob/btoa and base64 conversion helpers

Finding ID: `NPS-517B5A4E1913`

File: `src/v4/core/util.ts`

The base64/hex conversion helpers use atob/btoa and manual byte array construction. These are standard encoding utilities, not obfuscation. No hidden payloads are present and no data is transmitted externally.

### [low] Dual sync/async execution of caller-supplied function

Finding ID: `NPS-E949D5582ADD`

File: `v4/core/doc.cjs:18`

In `write(arg)`, if `arg` is a function it is invoked twice: once with `{ execution: "sync" }` and once with `{ execution: "async" }`. This pattern mirrors documented `magicast`/`ast-types`-style code generation usage, but invoking a callback twice with the same `Doc` instance and different flags is a control-flow oddity worth reviewing: a callback that mutates `this.content` non-idempotently can duplicate or corrupt generated code, and the `async` pass suggests execution paths not fully visible in this file.

### [low] dynamic_code_execution

Finding ID: `NPS-AFBA2C5A0956`

File: `v4/core/schemas.js`

The file uses new Function/compile for JIT code generation in $ZodObjectJIT (Doc.compile). This is a legitimate optimization in Zod for object parsing. It does not use external/untrusted input to compile code; it generates code from schema shape keys after escaping them via util.esc. No eval, no process spawning, no network I/O.

### [low] Insecure randomness

Finding ID: `NPS-FC520033F63E`

File: `v4/core/util.cjs`

`randomString` uses `Math.random()` to generate strings. This is not cryptographically secure and may be inappropriate for security-sensitive contexts (e.g., token generation), though within zod it is likely only used for internal identifiers.

### [low] Proxy/reflection utilities

Finding ID: `NPS-739AF35A7615`

File: `v4/core/util.cjs`

`createTransparentProxy` and various `Reflect.*` operations allow unrestricted property interception, which could be misused if applied to security-sensitive objects, though by itself it is a normal library utility.

### [low] Environment detection

Finding ID: `NPS-1EE6306C44BC`

File: `v4/core/util.cjs`

The `allowsEval` getter inspects `navigator.userAgent` for `Cloudflare`; behavior differing by environment can be a fingerprinting/evasion pattern, though here it plausibly reflects CSP/workerd constraints.

### [low] Prototype pollution potential

Finding ID: `NPS-2E98581A0372`

File: `v4/core/util.js:106`

The `assignProp` and `mergeDefs` functions use `Object.defineProperty` and `Object.assign` with user-controlled keys (e.g., `prop`, descriptors from `defs`). While these are internal utilities, if exposed to untrusted input, they could allow modification of object prototypes or injection of malicious properties. However, in the context of schema definition (zod library), the inputs are typically developer-controlled.

### [low] Insecure randomness

Finding ID: `NPS-9BDA4C8DB81B`

File: `v4/core/util.js:124`

The `randomString` function uses `Math.random()`, which is not cryptographically secure. If this function is used for generating tokens, nonces, or other security-sensitive values, it could introduce predictability. It appears to be a utility for generating random strings, but the naming and general-purpose nature warrant caution.

### [low] Global object access

Finding ID: `NPS-FB89ADF97E0F`

File: `v4/core/util.js:133`

The `captureStackTrace` constant references `Error.captureStackTrace`, which is a V8-specific extension. This is not malicious but indicates environment-specific behavior. No security risk directly.

### [low] Dynamic code execution capability

Finding ID: `NPS-C78E75D32C71`

File: `v4/core/util.js:142`

The `allowsEval` function uses `new Function('')` to test whether dynamic code evaluation is allowed in the current environment. While this specific call does not execute attacker-controlled code, the presence of this capability check suggests the library may conditionally use eval/Function elsewhere, which is a code smell and potential risk if inputs are not properly sanitized.

### [low] Potential information disclosure via errors

Finding ID: `NPS-F0FC3CA07A0F`

File: `v4/core/util.js:361`

The `finalizeIssue` function constructs error messages and deletes certain fields (`inst`, `continue`, `input`). If not properly configured, error messages might include sensitive input data. However, there is logic to delete `input` unless `ctx?.reportInput` is true, which is a reasonable safeguard.

### [low] Use of `atob`/`btoa`

Finding ID: `NPS-C98FB4600478`

File: `v4/core/util.js:392`

The base64 encoding/decoding functions use `atob` and `btoa`, which are standard in browsers and Node.js. No obfuscation or malicious payload is detected. However, these functions are often used in encoded payloads; here they appear to be legitimate codec utilities.

### [low] Deprecated alias

Finding ID: `NPS-7FBA43DB92FE`

File: `v4/locales/ua.cjs`

This file only re-exports the Ukrainian locale from './uk.cjs' and marks the previous 'ua' locale as deprecated. It contains no suspicious imports, network calls, environment access, dynamic execution, or process spawning.

## Files reviewed

- `src/v4/core/doc.ts` (medium): Contains a Function constructor-based dynamic code execution pattern in compile(), which is a code-injection risk if untrusted input reaches its arguments, though no overt malicious behavior was found.
- `src/v4/core/registries.ts` (medium): No data exfiltration, credential harvesting, obfuscation, or malicious execution was found; the only concerns are the import-time mutation of globalThis and heavy recursive type utilities, which warrant a warning but not a critical rating.
- `v4/core/doc.cjs` (medium): File contains dynamic function construction via the `Function` constructor with assembled source and an unusual dual sync/async callback invocation, but no network, filesystem, environment harvesting, or process-spawning behavior was observed.
- `v4/core/doc.js` (medium): The file uses dynamic code generation via the `Function` constructor, which is a potential code injection risk, but no other malicious patterns were detected.
- `v4/core/util.cjs` (medium): The file is a standard zod utility module with no network, filesystem, process, or exfiltration activity, but contains `Function`-based eval detection and non-cryptographic randomness worth noting.
- `v4/core/util.js` (medium): The file contains utility functions for a schema validation library (likely zod) with no clear malicious intent; a few low-severity code smells such as the use of `new Function` for capability detection and `Math.random` for string generation were noted, but no data exfiltration, backdoors, or process spawning were detected.
- `index.cjs` (safe): No malicious patterns detected; the code is standard TypeScript/CommonJS interop boilerplate re-exporting from a local module.
- `index.js` (safe): Cleared by Jev triage; no further analysis needed
- `locales/index.cjs` (safe): No malicious patterns detected; the file only re-exports locale definitions using standard TypeScript helper functions.
- `locales/index.js` (safe): Cleared by Jev triage; no further analysis needed
- `mini/index.cjs` (safe): No malicious patterns detected; the file is a standard TypeScript-generated CommonJS re-export shim.
- `mini/index.js` (safe): Cleared by Jev triage; no further analysis needed
- `src/index.ts` (safe): Cleared by Jev triage; no further analysis needed
- `src/locales/index.ts` (safe): Cleared by Jev triage; no further analysis needed
- `src/mini/index.ts` (safe): Cleared by Jev triage; no further analysis needed
- `src/v3/ZodError.ts` (safe): Cleared by Jev triage; no further analysis needed
- `src/v3/benchmarks/datetime.ts` (safe): Cleared by Jev triage; no further analysis needed
- `src/v3/benchmarks/discriminatedUnion.ts` (safe): Cleared by Jev triage; no further analysis needed
- `src/v3/benchmarks/index.ts` (safe): No malicious patterns detected; the file is a standard benchmark runner that reads CLI arguments and runs in-memory benchmarks without network, filesystem, or process-spawning operations.
- `src/v3/benchmarks/ipv4.ts` (safe): Cleared by Jev triage; no further analysis needed
- `src/v3/benchmarks/object.ts` (safe): Cleared by Jev triage; no further analysis needed
- `src/v3/benchmarks/primitives.ts` (safe): Cleared by Jev triage; no further analysis needed
- `src/v3/benchmarks/realworld.ts` (safe): No malicious patterns detected; the code is a standard Zod validation benchmark with no network, filesystem, process, or obfuscated behavior.
- `src/v3/benchmarks/string.ts` (safe): Cleared by Jev triage; no further analysis needed
- `src/v3/benchmarks/union.ts` (safe): Cleared by Jev triage; no further analysis needed
- `src/v3/errors.ts` (safe): Cleared by Jev triage; no further analysis needed
- `src/v3/external.ts` (safe): Cleared by Jev triage; no further analysis needed
- `src/v3/helpers/enumUtil.ts` (safe): Cleared by Jev triage; no further analysis needed
- `src/v3/helpers/errorUtil.ts` (safe): Cleared by Jev triage; no further analysis needed
- `src/v3/helpers/parseUtil.ts` (safe): Cleared by Jev triage; no further analysis needed
- `src/v3/helpers/partialUtil.ts` (safe): Cleared by Jev triage; no further analysis needed
- `src/v3/helpers/typeAliases.ts` (safe): Cleared by Jev triage; no further analysis needed
- `src/v3/helpers/util.ts` (safe): Cleared by Jev triage; no further analysis needed
- `src/v3/index.ts` (safe): Cleared by Jev triage; no further analysis needed
- `src/v3/locales/en.ts` (safe): Cleared by Jev triage; no further analysis needed
- `src/v3/standard-schema.ts` (safe): Cleared by Jev triage; no further analysis needed
- `src/v4-mini/index.ts` (safe): Cleared by Jev triage; no further analysis needed
- `src/v4/classic/checks.ts` (safe): Cleared by Jev triage; no further analysis needed
- `src/v4/classic/coerce.ts` (safe): Cleared by Jev triage; no further analysis needed
- `src/v4/classic/compat.ts` (safe): Cleared by Jev triage; no further analysis needed
- `src/v4/classic/errors.ts` (safe): Cleared by Jev triage; no further analysis needed
- `src/v4/classic/external.ts` (safe): This is a legitimate zod re-export module with only a benign top-level locale initialization side effect; no malicious patterns detected.
- `src/v4/classic/index.ts` (safe): Cleared by Jev triage; no further analysis needed
- `src/v4/classic/iso.ts` (safe): Cleared by Jev triage; no further analysis needed
- `src/v4/classic/parse.ts` (safe): Cleared by Jev triage; no further analysis needed
- `src/v4/classic/schemas.ts` (safe): Cleared by Jev triage; no further analysis needed
- `src/v4/core/api.ts` (safe): Cleared by Jev triage; no further analysis needed
- `src/v4/core/checks.ts` (safe): This is the Zod validation library's check definitions; it contains no network calls, dynamic execution, credential access, or other malicious patterns.
- `src/v4/core/config.ts` (safe): Cleared by Jev triage; no further analysis needed
- `src/v4/core/core.ts` (safe): No malicious patterns detected; the file contains only Zod core constructor utilities and type helpers with no network, filesystem, process, or dynamic execution behavior.
- `src/v4/core/errors.ts` (safe): Cleared by Jev triage; no further analysis needed
- `src/v4/core/index.ts` (safe): Cleared by Jev triage; no further analysis needed
- `src/v4/core/json-schema.ts` (safe): Cleared by Jev triage; no further analysis needed
- `src/v4/core/parse.ts` (safe): Cleared by Jev triage; no further analysis needed
- `src/v4/core/regexes.ts` (safe): This file contains only regular expression definitions for validation purposes and imports a local utility module; no malicious patterns, dynamic code execution, network activity, or obfuscation were detected.
- `src/v4/core/standard-schema.ts` (safe): Cleared by Jev triage; no further analysis needed
- `src/v4/core/to-json-schema.ts` (safe): Legitimate Zod library JSON Schema conversion code with no malicious patterns detected.
- `src/v4/core/util.ts` (safe): The file is a collection of type definitions and utility helpers for a schema validation library (Zod v4); no malicious patterns such as exfiltration, credential harvesting, backdoors, process spawning, or encoded payloads were detected, only a benign `new Function` capability probe and a cryptographically weak random string helper.
- `src/v4/core/versions.ts` (safe): Cleared by Jev triage; no further analysis needed
- `src/v4/core/zsf.ts` (safe): Cleared by Jev triage; no further analysis needed
- `src/v4/index.ts` (safe): Cleared by Jev triage; no further analysis needed
- `src/v4/locales/ar.ts` (safe): Cleared by Jev triage; no further analysis needed
- `src/v4/locales/az.ts` (safe): Cleared by Jev triage; no further analysis needed
- `src/v4/locales/be.ts` (safe): Cleared by Jev triage; no further analysis needed
- `src/v4/locales/bg.ts` (safe): Cleared by Jev triage; no further analysis needed
- `src/v4/locales/ca.ts` (safe): Cleared by Jev triage; no further analysis needed
- `src/v4/locales/cs.ts` (safe): Cleared by Jev triage; no further analysis needed
- `src/v4/locales/da.ts` (safe): Cleared by Jev triage; no further analysis needed
- `src/v4/locales/de.ts` (safe): Cleared by Jev triage; no further analysis needed
- `src/v4/locales/en.ts` (safe): Cleared by Jev triage; no further analysis needed
- `src/v4/locales/eo.ts` (safe): Cleared by Jev triage; no further analysis needed
- `src/v4/locales/es.ts` (safe): Cleared by Jev triage; no further analysis needed
- `src/v4/locales/fa.ts` (safe): Cleared by Jev triage; no further analysis needed
- `src/v4/locales/fi.ts` (safe): Cleared by Jev triage; no further analysis needed
- `src/v4/locales/fr-CA.ts` (safe): Cleared by Jev triage; no further analysis needed
- `src/v4/locales/fr.ts` (safe): Cleared by Jev triage; no further analysis needed
- `src/v4/locales/he.ts` (safe): Cleared by Jev triage; no further analysis needed
- `src/v4/locales/hu.ts` (safe): Cleared by Jev triage; no further analysis needed
- `src/v4/locales/id.ts` (safe): Cleared by Jev triage; no further analysis needed
- `src/v4/locales/index.ts` (safe): Cleared by Jev triage; no further analysis needed
- `src/v4/locales/is.ts` (safe): Cleared by Jev triage; no further analysis needed
- `src/v4/locales/it.ts` (safe): Cleared by Jev triage; no further analysis needed
- `src/v4/locales/ja.ts` (safe): Cleared by Jev triage; no further analysis needed
- `src/v4/locales/ka.ts` (safe): Cleared by Jev triage; no further analysis needed
- `src/v4/locales/kh.ts` (safe): Cleared by Jev triage; no further analysis needed
- `src/v4/locales/km.ts` (safe): Cleared by Jev triage; no further analysis needed
- `src/v4/locales/ko.ts` (safe): Cleared by Jev triage; no further analysis needed
- `src/v4/locales/lt.ts` (safe): Cleared by Jev triage; no further analysis needed
- `src/v4/locales/mk.ts` (safe): Cleared by Jev triage; no further analysis needed
- `src/v4/locales/ms.ts` (safe): Cleared by Jev triage; no further analysis needed
- `src/v4/locales/nl.ts` (safe): Cleared by Jev triage; no further analysis needed
- `src/v4/locales/no.ts` (safe): Cleared by Jev triage; no further analysis needed
- `src/v4/locales/ota.ts` (safe): Cleared by Jev triage; no further analysis needed
- `src/v4/locales/pl.ts` (safe): Cleared by Jev triage; no further analysis needed
- `src/v4/locales/ps.ts` (safe): Cleared by Jev triage; no further analysis needed
- `src/v4/locales/pt.ts` (safe): Cleared by Jev triage; no further analysis needed
- `src/v4/locales/ru.ts` (safe): Cleared by Jev triage; no further analysis needed
- `src/v4/locales/sl.ts` (safe): Cleared by Jev triage; no further analysis needed
- `src/v4/locales/sv.ts` (safe): Cleared by Jev triage; no further analysis needed
- `src/v4/locales/ta.ts` (safe): Cleared by Jev triage; no further analysis needed
- `src/v4/locales/th.ts` (safe): Cleared by Jev triage; no further analysis needed
- `src/v4/locales/tr.ts` (safe): Cleared by Jev triage; no further analysis needed
- `src/v4/locales/ua.ts` (safe): Cleared by Jev triage; no further analysis needed
- `src/v4/locales/uk.ts` (safe): Cleared by Jev triage; no further analysis needed
- `src/v4/locales/ur.ts` (safe): Cleared by Jev triage; no further analysis needed
- `src/v4/locales/vi.ts` (safe): Cleared by Jev triage; no further analysis needed
- `src/v4/locales/yo.ts` (safe): Cleared by Jev triage; no further analysis needed
- `src/v4/locales/zh-CN.ts` (safe): Cleared by Jev triage; no further analysis needed
- `src/v4/locales/zh-TW.ts` (safe): Cleared by Jev triage; no further analysis needed
- `src/v4/mini/checks.ts` (safe): Cleared by Jev triage; no further analysis needed
- `src/v4/mini/coerce.ts` (safe): Cleared by Jev triage; no further analysis needed
- `src/v4/mini/external.ts` (safe): Cleared by Jev triage; no further analysis needed
- `src/v4/mini/index.ts` (safe): Cleared by Jev triage; no further analysis needed
- `src/v4/mini/iso.ts` (safe): Cleared by Jev triage; no further analysis needed
- `src/v4/mini/parse.ts` (safe): Cleared by Jev triage; no further analysis needed
- `src/v4/mini/schemas.ts` (safe): Cleared by Jev triage; no further analysis needed
- `v3/ZodError.cjs` (safe): Cleared by Jev triage; no further analysis needed
- `v3/ZodError.js` (safe): Cleared by Jev triage; no further analysis needed
- `v3/errors.cjs` (safe): No malicious patterns detected; the file only manages error message localization maps without network, filesystem, or process operations.
- `v3/errors.js` (safe): Cleared by Jev triage; no further analysis needed
- `v3/external.cjs` (safe): No malicious patterns detected; this file only contains standard TypeScript CommonJS re-export boilerplate.
- `v3/external.js` (safe): Cleared by Jev triage; no further analysis needed
- `v3/helpers/enumUtil.cjs` (safe): No malicious patterns detected
- `v3/helpers/enumUtil.js` (safe): Cleared by Jev triage; no further analysis needed
- `v3/helpers/errorUtil.cjs` (safe): No malicious patterns detected
- `v3/helpers/errorUtil.js` (safe): No malicious patterns detected; the code is a simple utility for converting error messages to objects or strings.
- `v3/helpers/parseUtil.cjs` (safe): No malicious patterns detected; the file contains only standard validation and error-handling utilities from a Zod-like library.
- `v3/helpers/parseUtil.js` (safe): Cleared by Jev triage; no further analysis needed
- `v3/helpers/partialUtil.cjs` (safe): No malicious patterns detected
- `v3/helpers/partialUtil.js` (safe): Cleared by Jev triage; no further analysis needed
- `v3/helpers/typeAliases.cjs` (safe): No malicious patterns detected
- `v3/helpers/typeAliases.js` (safe): Cleared by Jev triage; no further analysis needed
- `v3/helpers/util.cjs` (safe): The code is a utility module for the Zod validation library and contains no malicious patterns, network calls, file system access, or dynamic code execution.
- `v3/helpers/util.js` (safe): No malicious patterns detected
- `v3/index.cjs` (safe): No malicious patterns detected
- `v3/index.js` (safe): Cleared by Jev triage; no further analysis needed
- `v3/locales/en.cjs` (safe): Cleared by Jev triage; no further analysis needed
- `v3/locales/en.js` (safe): Cleared by Jev triage; no further analysis needed
- `v3/standard-schema.cjs` (safe): No malicious patterns detected
- `v3/standard-schema.js` (safe): Cleared by Jev triage; no further analysis needed
- `v4-mini/index.cjs` (safe): No malicious patterns detected; the file is a standard TypeScript-generated CommonJS re-export shim.
- `v4-mini/index.js` (safe): Cleared by Jev triage; no further analysis needed
- `v4/classic/checks.cjs` (safe): No malicious patterns detected; the file is a straightforward re-export module for Zod validation checks.
- `v4/classic/checks.js` (safe): Cleared by Jev triage; no further analysis needed
- `v4/classic/coerce.cjs` (safe): No malicious patterns detected; the code is standard TypeScript-compiled helper functions for Zod schema coercion with no suspicious behavior.
- `v4/classic/coerce.js` (safe): Cleared by Jev triage; no further analysis needed
- `v4/classic/compat.cjs` (safe): This is a standard Zod v3 compatibility shim using TypeScript's commonjs interop helpers to re-export core modules and deprecated APIs; no malicious patterns detected.
- `v4/classic/compat.js` (safe): Cleared by Jev triage; no further analysis needed
- `v4/classic/errors.cjs` (safe): No malicious patterns detected
- `v4/classic/errors.js` (safe): Cleared by Jev triage; no further analysis needed
- `v4/classic/external.cjs` (safe): No malicious patterns detected; the code is standard TypeScript/CommonJS module boilerplate and re-exports for the Zod library.
- `v4/classic/external.js` (safe): No malicious patterns detected
- `v4/classic/index.cjs` (safe): No malicious patterns detected
- `v4/classic/index.js` (safe): Cleared by Jev triage; no further analysis needed
- `v4/classic/iso.cjs` (safe): No malicious patterns detected; the code is a standard TypeScript-compiled Zod library module for ISO date/time schemas with only benign module import/export logic.
- `v4/classic/iso.js` (safe): No malicious patterns detected
- `v4/classic/parse.cjs` (safe): No malicious patterns detected; the file contains standard TypeScript/CommonJS interop helpers and re-exports of Zod validation functions.
- `v4/classic/parse.js` (safe): Cleared by Jev triage; no further analysis needed
- `v4/classic/schemas.cjs` (safe): No malicious patterns detected
- `v4/classic/schemas.js` (safe): No malicious patterns detected; this is legitimate Zod schema definition code with no exfiltration, dynamic execution, network, or process-spawning behavior.
- `v4/core/api.cjs` (safe): No malicious patterns detected
- `v4/core/api.js` (safe): No malicious patterns detected; this is legitimate Zod validation library code with no data exfiltration, credential harvesting, obfuscation, process spawning, or other suspicious behavior.
- `v4/core/checks.cjs` (safe): No malicious patterns detected; the code is a standard Zod validation library module with no exfiltration, credential harvesting, obfuscation, or dynamic code execution.
- `v4/core/checks.js` (safe): No malicious patterns detected in this Zod validation checks module; it only contains schema validation logic with no network, filesystem, process, or dynamic code execution activity.
- `v4/core/core.cjs` (safe): No malicious patterns detected; the code is a legitimate utility module from the Zod validation library with no network, filesystem, process execution, or obfuscated behavior.
- `v4/core/core.js` (safe): No malicious patterns detected
- `v4/core/errors.cjs` (safe): No malicious patterns detected; the file is a standard TypeScript-compiled Zod error formatting utility with no network, filesystem, process, or dynamic execution behavior.
- `v4/core/errors.js` (safe): Cleared by Jev triage; no further analysis needed
- `v4/core/index.cjs` (safe): No malicious patterns detected; the file contains standard TypeScript/CommonJS module re-export boilerplate.
- `v4/core/index.js` (safe): Cleared by Jev triage; no further analysis needed
- `v4/core/json-schema.cjs` (safe): No malicious patterns detected
- `v4/core/json-schema.js` (safe): Cleared by Jev triage; no further analysis needed
- `v4/core/parse.cjs` (safe): This is a legitimate Zod validation library file with standard TypeScript helper functions and parsing logic, containing no malicious patterns.
- `v4/core/parse.js` (safe): No malicious patterns detected
- `v4/core/regexes.cjs` (safe): No malicious patterns detected; the file contains only regex definitions for common validation patterns and helper functions with no external I/O, dynamic code execution, or suspicious behavior.
- `v4/core/regexes.js` (safe): No malicious patterns detected
- `v4/core/registries.cjs` (safe): No malicious patterns detected; the code implements a schema registry with WeakMap/Map storage and standard Zod symbol exports.
- `v4/core/registries.js` (safe): No malicious patterns detected; the code implements a benign schema metadata registry using WeakMap/Map with no network, filesystem, process execution, or obfuscated code.
- `v4/core/schemas.cjs` (safe): No malicious patterns detected; this is a legitimate Zod schema validation library file with no data exfiltration, dynamic code execution, or credential harvesting.
- `v4/core/schemas.js` (safe): Zod schema implementation contains only legitimate validation logic; dynamic code generation is confined to internal JIT compilation of schema shapes without external input or malicious behavior.
- `v4/core/standard-schema.cjs` (safe): No malicious patterns detected
- `v4/core/standard-schema.js` (safe): Cleared by Jev triage; no further analysis needed
- `v4/core/to-json-schema.cjs` (safe): No malicious patterns detected; the code is a standard JSON Schema generator from Zod with no network, filesystem, credential, or dynamic execution activity.
- `v4/core/to-json-schema.js` (safe): No malicious patterns detected; the code is a legitimate JSON Schema generator for Zod with no network, filesystem, process, or dynamic code execution activities.
- `v4/core/versions.cjs` (safe): No malicious patterns detected
- `v4/core/versions.js` (safe): Cleared by Jev triage; no further analysis needed
- `v4/index.cjs` (safe): No malicious patterns detected
- `v4/index.js` (safe): Cleared by Jev triage; no further analysis needed
- `v4/locales/ar.cjs` (safe): No malicious patterns detected
- `v4/locales/ar.js` (safe): Cleared by Jev triage; no further analysis needed
- `v4/locales/az.cjs` (safe): No malicious patterns detected; the file is a standard localization module for Zod validation errors in Azerbaijani.
- `v4/locales/az.js` (safe): Cleared by Jev triage; no further analysis needed
- `v4/locales/be.cjs` (safe): No malicious patterns detected
- `v4/locales/be.js` (safe): Cleared by Jev triage; no further analysis needed
- `v4/locales/bg.cjs` (safe): No malicious patterns detected; this is a standard localization/error message file for a validation library with no network, filesystem, process, or dynamic code execution activity.
- `v4/locales/bg.js` (safe): Cleared by Jev triage; no further analysis needed
- `v4/locales/ca.cjs` (safe): No malicious patterns detected
- `v4/locales/ca.js` (safe): Cleared by Jev triage; no further analysis needed
- `v4/locales/cs.cjs` (safe): No malicious patterns detected
- `v4/locales/cs.js` (safe): Cleared by Jev triage; no further analysis needed

## Version ranges

1 of 4 scanned versions of zod are flagged: 4.6.5 (critical). The latest scanned version, 4.6.5, is critical risk. Only versions we have scanned are listed; unscanned versions between them are not covered.

- 4.6.5 (`4.6.5`): critical (Dynamic code execution +4 more)
- 3.25.76 – 4.1.13 (`>=3.25.76 <=4.1.13`): medium (Dynamic code execution +2 more)
- 3.23.8 (`3.23.8`): not scanned
- 3.22.4 (`3.22.4`): clean
- Flagged file `v4/core/checks.cjs` (critical) present in 4.6.5
- Flagged file `v4/core/doc.cjs` (critical) present in 4.6.5; finding IDs `NPS-9534A8F558A8`, `NPS-22B097E9EAFF`, `NPS-ADAE75B39B3B`

## Scanned versions

- [4.6.5](https://security.togoder.click/npm/zod@4.6.5): critical, 2026-10-06T14:25:39.000Z
- [4.1.13](https://security.togoder.click/npm/zod@4.1.13): medium, 2026-10-04T16:54:46.000Z
- [3.25.76](https://security.togoder.click/npm/zod@3.25.76): medium, 2026-10-04T16:54:47.000Z
- [3.22.4](https://security.togoder.click/npm/zod@3.22.4): safe, 2026-10-04T16:54:43.000Z

AI analysis is guidance, not a guarantee. Methodology: https://security.togoder.click/methodology
