Togoder security

npm package security report

zod@4.6.5 security report

Critical: dangerous or likely malicious code found.

Critical risk Version 4.6.5 Files reviewed 375 Size 3.5 MB Scanned

Summary

Togoder Security scanned the npm package zod@4.6.5 on Oct 6, 2026. An AI review of 375 source files produced 1 critical, 3 high, 12 medium, 46 low severity findings. At least one finding describes dangerous behavior such as code that runs at install time, credential access or data exfiltration. Do not install this version until you have reviewed the findings below.

1
critical
3
high
12
medium
46
low

Findings 62

critical

Dynamic code execution

NPS-9534A8F558A8

The compile() method uses Function constructor (new F(...Object.keys(this.closed), ...)) to dynamically compile and execute a function from the document's content and closed-over arguments. This is equivalent to eval/new Function and can execute arbitrary code at runtime. If an attacker can control this.content, this.args, or this.closed (e.g., via deserialization or untrusted input), this leads to remote code execution.

v4/core/doc.cjs:41
high

Dynamic code execution via new Function

NPS-5F5E411E3391

The code uses new Function (aliased as F) with dynamically generated JavaScript source code built from schema definitions. While this is core to the AOT compilation design of this validation library, dynamic code generation is a high-risk pattern that can be abused if attacker-controlled values reach the codegen path. Notably, the numericOperand() function contains an explicit comment acknowledging this risk: bounds reaching generated source verbatim could allow arbitrary statement injection if types are not enforced. The author mitigates this by validating that bounds are finite numbers before emitting them, but this remains a dangerous pattern requiring careful review.

v4/core/compile.js:174
high

Dynamic code execution

NPS-22B097E9EAFF

write() accepts functions and invokes them with the Doc instance (arg(this, { execution: "sync" }) and arg(this, { execution: "async" })). Combined with compile(), this forms a dynamic code generation pipeline where user-supplied callbacks can inject arbitrary strings into the compiled function body.

v4/core/doc.cjs:22
high

Encoded/obfuscated payload construction

NPS-ADAE75B39B3B

The compile() method builds a function string by interpolating this.closed keys, this.args, and this.content directly into a function body template. This pattern (return function (${args}) { ... }) is a common vector for code injection when any of these inputs are attacker-controlled.

v4/core/doc.cjs:41
medium

dynamic code execution

NPS-464DC8B143DD

The module imports and invokes a compiler (./v4/core/compile.cjs) that, per the accompanying comments, may generate code via new Function. The shim respects globalConfig.jitless to avoid eval in CSP/no-eval environments, which indicates dynamic code generation is part of the design. This is a legitimate JIT/compilation feature but is a potential vector for code execution if the compiler is compromised or fed untrusted schema definitions.

compile.cjs
medium

top-level side effect on import

NPS-2F72A1B28FC3

The file mutates core.globalConfig.postProcessor at module evaluation time and is intended to be imported for side effects. This globally alters parsing behavior for all schemas in the process, including those from other libraries, without explicit opt-in beyond the import statement. Any code importing this module changes runtime semantics process-wide.

src/compile.ts:14
medium

Dynamic code execution

NPS-8FADB9BF8F4A

The module builds validator functions via new Function(...) (const F = Function; const factory = new F(...constantNames, factoryCode)). While this is the documented purpose of the AOT compiler (generating a fast-path parser from a Zod schema), it is dynamic code execution. The generated source is built from schema definitions, and the code explicitly guards against source-injection via numericOperand (which rejects non-number bounds because a string bound would be emitted verbatim into generated source). This is a legitimate, defensively-guarded use, but it remains a new Function sink that warrants review in a supply-chain context.

src/v4/core/compile.ts:350
medium

Dynamic code execution

NPS-23A524B6FD8E

The compile() method uses new Function(...) to construct and execute a function from string content stored in this.content and closure names from this.closed. While this appears to be a legitimate code-generation mechanism (similar to template engines), dynamic code execution via the Function constructor can be abused to run arbitrary code if the Doc content is influenced by untrusted input, and it bypasses CSP and static analysis.

src/v4/core/doc.ts:39
medium

Dynamic code execution via constructor

NPS-81A99AEED74D

The module uses core.$constructor and a chain of dynamically constructed check functions. While not directly malicious in this file, the heavy reliance on runtime function construction and prototype manipulation (inst._zod.check = ...) makes behavior dependent on external definitions in core.cjs, regexes.cjs, and util.cjs. This pattern is used by zod v4 for validation but is also a common obfuscation/behavior-injection vector if any of the source modules are tampered with.

v4/core/checks.cjs:48
medium

Use of eval-like constructor / CSP bypass surface

NPS-EC0A20358DF4

const F = Function; followed by new F(...constantNames, factoryCode) is an alias for the Function constructor, i.e. implicit eval. This is intrinsic to the compiler's purpose, but security reviewers should note it executes dynamically constructed code in the host realm and can be blocked or risky under strict CSP environments; the code catches this as ZodCompileUnsupportedError and falls back to the runtime parser.

v4/core/compile.cjs:159
medium

Dynamic code execution

NPS-98DDC92F7429

The file generates JavaScript source code at runtime and executes it via new Function(...). This is core to the AOT compiler design (Zod compile fast path), but new Function is a dynamic code execution primitive. The generated code embeds user-supplied callbacks, regex patterns, bounds, and literal values as hoisted constants or inline source. While the code includes backstops such as numericOperand() type checking and util.esc() escaping to mitigate source injection, any flaw in those guards could allow arbitrary code execution because generated source is constructed from schema definitions. The options.debug path also attaches generated code to fn.code.

v4/core/compile.cjs:161
medium

Potential code injection via interpolated values in generated source

NPS-A9D2ADC677B0

Multiple codegen paths interpolate schema-derived values directly into generated JavaScript source using template literals (e.g., def.value}n, ${prefix.length}, ${accessor}[${util.esc(k)}]). util.esc is used for string escaping in some places, but other interpolations rely on the caller having validated types. The numericOperand guard is a backstop rather than a complete defense. If schema construction paths (JSON Schema import, programmatic mutation) bypass these checks, arbitrary code execution in the generated function is possible.

v4/core/compile.js
medium

Dynamic code generation as core mechanism

NPS-994058829AFD

The compileFn function builds a factory via new Function(...constantNames, factoryCode) and executes it. This means user-supplied schema definitions and callbacks are hoisted into generated code and executed. While this is the intended design of a compiler, it substantially expands the attack surface: any bug in the codegen escaping or type-checking logic becomes a code execution vulnerability.

v4/core/compile.js
medium

Global mutable configuration hook

NPS-7CCF318D51C5

The code defines and reads a global object globalThis.__zod_globalConfig and exposes a config() function that allows any code to mutate global configuration. More notably, the schema constructor function _ invokes globalThis.__zod_globalConfig?.postProcessor on every constructed schema instance. Any other module in the same process can install a postProcessor that receives every created schema object, giving arbitrary third-party code a hook to inspect and tamper with all Zod schema instances at runtime. This is an undocumented global side-effect and an implicit extension point that could be abused by malicious packages to intercept or mutate schema objects.

v4/core/core.js:128
medium

Use of Function constructor

NPS-DDBFCB1597C7

The code explicitly uses 'const F = Function;' and then 'new F(...)' to generate executable code. While the content is generated internally from writes to the Doc instance, any external input that reaches the write() method could lead to arbitrary code execution when compile() is called.

v4/core/doc.js:28
medium

Dynamic code execution

NPS-81D7292E02B0

The compile() method uses the Function constructor to create a new function from the accumulated content string. This is a form of dynamic code execution equivalent to eval, which can be dangerous if the content is influenced by untrusted input.

v4/core/doc.js:30
low

import-time side effects

NPS-BFE94B36FC5D

This file is a side-effect-only module that, upon import, mutates core.globalConfig.postProcessor and monkey-patches inst._zod.run on every schema constructed afterward. It runs top-level code at import time, modifying global behavior of the zod library. While documented and intentional, this kind of global monkey-patching in a package can surprise consumers and alter runtime semantics (e.g., silently replacing the parser with a compiled version).

compile.cjs
low

runtime behavior modification

NPS-2349F20DDBB5

The postProcessor wraps and replaces inst._zod.run with a shim that conditionally swaps in compiled execution paths. If compilation fails, it silently falls back to the original runtime. This is not malicious per se, but the pattern of globally intercepting schema execution could be abused in a supply-chain compromise to alter validation results (e.g., skipping checks) if the underlying compile module were tampered with.

compile.cjs
low

module export freezing

NPS-F28446128293

The 'seal-cjs-exports' IIFE converts getters to fixed values and calls Object.freeze(exports), preventing downstream modification of the module's exports. This is defensive/anti-tampering and not malicious, but it does make the module harder to patch or audit at runtime.

compile.cjs
low

dynamic code execution surface

NPS-DF59DB34AC3C

The module installs a global postProcessor that invokes compile() on schemas. The code explicitly references JIT compilation and guards against new Function via the jitless config, indicating that the compiler generates functions dynamically. While the guard mitigates CSP bypass, this module still triggers dynamic code generation at parse time for any schema constructed after import, which is a significant attack surface if the compiler has flaws.

src/compile.ts:14
low

global state mutation / monkey-patching

NPS-B3D8D244E841

The postProcessor replaces inst._zod.run on schema instances with a shim, and stores __originalRun on the function object. This is a form of runtime monkey-patching that modifies shared library behavior. While the code comments explain the rationale, it can cause subtle interactions (e.g., double-wrapping, recursion guard via compiling flag) that may be exploitable or cause unexpected behavior in downstream consumers.

src/compile.ts:43
low

Dynamic RegExp construction

NPS-4BBC2F11AEBF

User-supplied JSON Schema pattern and patternProperties values are passed directly to new RegExp(...) without validation or escaping. While not malicious itself, this could expose consumers to ReDoS or catastrophic backtracking if untrusted schemas are converted. It is a normal part of implementing JSON Schema semantics, not a security backdoor.

src/v4/classic/from-json-schema.ts
low

Prototype-pollution hardening

NPS-B01B2E299773

The code explicitly uses assignProp to write __proto__ keys as own properties instead of through the inherited setter, and guards Object.entries/keys usage. This is defensive, not malicious.

src/v4/classic/from-json-schema.ts
low

JSON round-trip normalization

NPS-2FBED41CF6EE

JSON.parse(JSON.stringify(schema)) is used to normalize input, which is a deliberate defense against cyclic structures, getters, and Proxies. No dynamic evaluation is involved.

src/v4/classic/from-json-schema.ts
low

Reflection and runtime schema introspection

NPS-1B00C9F3B31E

The compiler reflects over arbitrary user-supplied schemas and callbacks, hoisting user functions (def.fn, def.transform, def.catchValue, def.getter, check._zod.check, tx) into generated closures and invoking them. Errors thrown by these callbacks are intentionally propagated (throwAsync, transform helpers). This matches documented behavior but means any executable code attached to a schema will run during validation.

src/v4/core/compile.ts
low

Global symbol registration / sentinel leakage

NPS-96FDC8169933

Uses Symbol.for("zod.compile.invalid") and Symbol.for("zod.compile.fallback") in the global symbol registry. Benign in itself, but registers globally reachable sentinels that other code could in principle collide with.

src/v4/core/compile.ts:27
low

dynamic code execution probe

NPS-04ACF78EC0BB

The allowsEval cached function probes for dynamic code execution capability via new Function(""), but this is a feature-detection pattern (checking if CSP/jitless environments permit eval), not an execution of external or untrusted input. The result is discarded and the construction is wrapped in try/catch. This is a common pattern in libraries that want to conditionally optimize code paths based on environment capabilities.

src/v4/core/util.ts
low

Dynamic code execution

NPS-90C99EB88B62

The code uses an IIFE that calls Object.getOwnPropertyDescriptor and Object.defineProperty to freeze exports; however this is a common pattern for module sealing, not obfuscated malicious code execution.

v3/errors.cjs:21
low

Top-level code execution / export sealing

NPS-5E10234CDD2B

The file contains an immediately-invoked function expression (IIFE) that runs at import time, iterating over all exported properties, invoking their getters, and redefining them as non-configurable frozen values before calling Object.freeze(exports). While this pattern is used by some libraries to enforce immutable CommonJS exports, it executes arbitrary getter logic at module load and permanently mutates the module exports object. This can interfere with consumers and is an unusual pattern that warrants review, though it does not appear to exfiltrate data or execute external code.

v3/external.cjs:21
low

Dynamic getter invocation

NPS-15855FBA2433

The code calls desc.get() for every exported property whose descriptor defines a getter. If any re-exported module defines side-effecting getters, this would trigger those effects at import time. In this specific file the re-exported modules (errors, parseUtil, typeAliases, util, types, ZodError) are part of the Zod library and appear benign, but the mechanism itself is a potential vector for unexpected top-level execution.

v3/external.cjs:30
low

Top-level code execution

NPS-B3A4073463C8

The file executes code at import time, including a prototype manipulation initializer and an IIFE that seals/freezes the module exports. This is standard module initialization behavior, not a malicious install-time hook.

v4/classic/errors.cjs
low

Prototype mutation

NPS-B2717DA2D22D

The initializer lazily installs non-enumerable getter/setter methods on the prototype of ZodError instances. It explicitly guards against touching Object.prototype and Error.prototype via a WeakSet to avoid prototype pollution. This is a deliberate design choice, not an attack pattern.

v4/classic/errors.cjs
low

sealed exports pattern

NPS-C202812A8C37

The 'seal-cjs-exports' IIFE at the bottom freezes the exports object and converts getter properties into non-writable, non-configurable values. This is a defensive measure used by some bundlers (e.g. esbuild-style or tsup output for Zod) to ensure CommonJS interop consistency. It does not execute external code, access the filesystem, or perform network activity. Behavior is deterministic and limited to the module's own exports object.

v4/classic/iso.cjs:45
low

export sealing/freezing

NPS-D4E3D108B5BB

The file freezes its exports and replaces getters with static values to prevent later tampering. This is a legitimate hardening pattern used by Zod, not a malicious behavior.

v4/classic/parse.cjs
low

Global prototype / object manipulation

NPS-E6010F034E57

Object.defineProperty on 'default', __createBinding, __setModuleDefault helpers mutate module exports. Standard TS/CommonJS interop, but the pattern combined with dynamic getter invocation in the sealing IIFE could be leveraged to force-evaluate attacker-injected getters if the package is compromised at publish time.

v4/core/checks.cjs:5
low

Dynamic RegExp construction from user-controlled strings

NPS-1150A5B87913

RegExp objects are dynamically constructed from def.includes, def.prefix, def.suffix in $ZodCheckIncludes, $ZodCheckStartsWith, $ZodCheckEndsWith. Values are passed through util.escapeRegex first, which mitigates ReDoS injection, but the pattern still takes runtime input into RegExp construction. This is legitimate validation logic for zod, not malicious.

v4/core/checks.cjs:331
low

Top-level execution at import time

NPS-F5A84ED7C8DE

The file executes an IIFE ('seal-cjs-exports') at module load time that enumerates all exports, invokes their getters, and freezes the exports object. Getters can run arbitrary code; while here they resolve to defined constructors, this pattern (firing property getters on import and freezing the module namespace) is unusual for a plain library module and can force evaluation of lazily-initialized code paths at import.

v4/core/checks.cjs:467
low

Expected validation logic

NPS-EDD5E444102F

The file implements Zod validation checks (min/max length, size, numeric bounds, regex/format checks, property validation, etc.) using constructor helpers. It imports only internal modules (core, regexes, util). No network, filesystem, process, environment, or dynamic code execution APIs are used. The eval-like comment in $ZodCheckProperty is a legitimate regex anchor comment, not dynamic code execution. No obfuscated payloads, credential harvesting, exfiltration, mining, or backdoor patterns are present.

v4/core/checks.js
low

Patching of parse/safeParse/run methods

NPS-CA889278A0E7

installCompiledUserMethods replaces parse and safeParse on the returned schema clone, and withParser replaces _zod.run. This is documented compiler behavior for schema objects only, not globals, and it captures originalRun/originalParse fallbacks. It is not a global monkey-patch, but it does mutate exported API surface and should be confirmed to not affect unrelated objects.

v4/core/compile.cjs:145
low

Getters invoked during generated validation

NPS-0B6AB5B1D13C

Generated code reads input properties once and calls .trim(), .toLowerCase(), .includes(), instanceof, %, etc. Object getters on untrusted input are invoked during fast-path validation (cached once per key, but still executed). This matches runtime parser behavior, though it means the compiled fast path is not safe for hostile objects with side-effecting getters unless the runtime parser has the same property.

v4/core/compile.cjs:1082
low

Prototype manipulation handling

NPS-0B4E6D6A6E72

The code explicitly guards against __proto__ keys in object shapes, records, and catchall loops (obj["__proto__"] prototype setter concerns). These guards appear defensive and correctness-oriented, but repeated handling of __proto__ and Object.getOwnPropertyNames/getOwnPropertySymbols walks indicates the compiler accepts attacker-influenced key names and must be audited to ensure the guards cannot be bypassed to cause prototype pollution in generated outputs.

v4/core/compile.cjs:1110
low

Invocation of user-supplied callbacks in generated code

NPS-7D1185359180

Multiple generated sections call user callbacks directly: refinements (def.fn), superRefine checks (check._zod.check), transforms, overwrite transforms, catch values, lazy getters, string-format predicates, and discriminated-union literals. These are expected schema-author-owned functions, but they are hoisted into generated source and invoked at parse time. The helpers generateTransformCheck, generatePipeCheck, and generateCustomRefineCheck spoof payload/addIssue and deliberately do not catch throws, allowing arbitrary exceptions from user code to propagate.

v4/core/compile.cjs:1289
low

No data exfiltration, network, filesystem, or process-spawning patterns detected

NPS-56C1570810EB

The file does not import or reference any network APIs, environment variables, credential files, child_process, shell commands, filesystem manipulation, or crypto wallet logic. No obfuscation or encoded payloads were found.

v4/core/compile.js
low

Modification of global Error.stackTraceLimit

NPS-3C599C8FB2EA

newError temporarily sets Error.stackTraceLimit = 0 and restores it. It handles failures, but it still mutates a shared global object at parse time. If the restore is interrupted (e.g., a getter/setter trap on Error, or concurrent async code), the global stack trace limit can be left in an altered state for the entire process. This is a global side-effect rather than a security compromise, but it is a cross-cutting mutation of a shared builtin.

v4/core/core.js:22
low

Top-level global side effect on import

NPS-3D199E5D0B68

At module import time the code runs (_a = globalThis).__zod_globalConfig ?? (_a.__zod_globalConfig = {}), unconditionally creating a global property on the host environment. Importing the package therefore mutates the global object, which is a side effect that can interact with other libraries or be used as a coordination channel by other packages.

v4/core/core.js:148
low

dynamic-code-execution

NPS-4CC687A273FA

The code wraps schema parse functions at runtime and manipulates prototype-like properties, but does not use eval, Function constructor, or any dynamic code execution from external input. The wrapping is internal to the Zod memoization logic.

v4/core/memoizer.cjs
low

install-time-execution

NPS-AF65CB852766

The file contains an IIFE at the bottom that seals and freezes exports at import time. This executes on module load but performs only local property descriptor inspection and freezing of its own exports; no network, filesystem, or process access.

v4/core/memoizer.cjs
low

global state pollution

NPS-BC3C88AD5DE4

The code assigns a global registry to globalThis.__zod_globalRegistry. This is expected Zod behavior for sharing a registry across module instances, not a malicious pattern. It only stores schema references and metadata locally and performs no network, filesystem, or process operations.

v4/core/registries.js:60
low

Import-time module sealing

NPS-F26A4FC95641

A top-level IIFE at the end of the file ('seal-cjs-exports') converts getter-only export properties into frozen data properties and calls Object.freeze(exports). This runs at import time but is a benign anti-tampering measure on the module's own exports; it does not touch global state, files, network, or processes.

v4/core/to-json-schema.cjs
low

Dynamic code execution probe

NPS-9B329B5A88BB

The allowsEval cached getter uses new Function("") to probe whether eval-like dynamic code execution is allowed. While wrapped in try/catch and gated by config/userAgent checks, it directly invokes the Function constructor, which is a red-flag pattern for dynamic code execution and could be abused if the cached result or configuration is tampered with. The code does not actually execute attacker-controlled strings, but the presence of new Function at module import time is noteworthy.

v4/core/util.cjs
low

Top-level execution on import

NPS-41C16C7CD885

The file contains a top-level IIFE 'seal-cjs-exports' that runs at import time, iterating over exports, invoking getters, and freezing the exports object. This is benign module hardening but constitutes code that executes on import. No network, filesystem, or process access is involved.

v4/core/util.cjs
low

Insecure randomness generation

NPS-5519D147D384

randomString uses Math.random() to generate strings. This is unsuitable for any security-sensitive use (tokens, IDs, nonces). The function is exported and could be misused by downstream callers expecting cryptographic randomness. This is a security-hygiene issue, not a malicious pattern.

v4/core/util.cjs
low

Prototype pollution surface

NPS-385520BA3E80

Several utilities manipulate object descriptors and prototypes (mergeDefs, createTransparentProxy, putProp, mirrorShape, defineLazy, defineLazyInternal, installLazyProp, members, derived). finalizeIssue explicitly skips __proto__ keys, indicating awareness of prototype pollution. The code generally guards against inherited setters with assignProp/own, but the extensive use of Reflect and Object.defineProperty on arbitrary keys is a potential attack surface if inputs are attacker-controlled.

v4/core/util.cjs
low

prototype-sensitive property writes

NPS-A82024CEA093

Helpers such as putProp, assignProp, deferProp, defineLazy, and defineLazyInternal use Object.defineProperty and guard with key in target. The code includes explicit defenses against __proto__ setter abuse and prototype pollution in putProp and finalizeIssue, indicating awareness of these risks rather than exploitation.

v4/core/util.js:120
low

weak randomness

NPS-473085D25553

randomString uses Math.random(), which is not cryptographically secure. This is a quality concern for security-sensitive use but not malicious; it appears intended for non-cryptographic identifiers.

v4/core/util.js:178
low

dynamic code execution probe

NPS-BE2AC035AEB6

The allowsEval helper uses new Function('') to detect whether CSP/JIT restrictions allow dynamic code evaluation. This is a capability probe with the throw swallowed and no untrusted input passed, matching the documented purpose in the surrounding comment; it does not execute attacker-controlled code.

v4/core/util.js:188
low

Sealed exports pattern

NPS-2933FF9824E9

The code freezes the exports object and converts getters to static values. This is a defensive pattern to prevent runtime modification and does not constitute malicious behavior.

v4/index.cjs
low

Deprecated alias

NPS-7FBA43DB92FE

This file only re-exports the Ukrainian locale from './uk.cjs' and marks the previous 'ua' locale as deprecated. It contains no suspicious imports, network calls, environment access, dynamic execution, or process spawning.

v4/locales/ua.cjs
low

Top-level code execution

NPS-B6527AE9C537

The IIFE at the end of the file runs at import time to seal/freeze the exports object. This is a benign pattern used to prevent mutation of exports and does not perform any malicious activity such as network access, file system manipulation, or process spawning.

v4/mini/deep-partial.cjs:60
low

Code that runs at import time

NPS-E6F1D042D337

An IIFE executes at module load to seal exports by converting getters to static values and freezing the exports object. This is a defensive measure to prevent export tampering, not malicious. It does not access external resources, environment variables, or execute dynamic code.

v4/mini/parse.cjs:18
low

Import-time side effects / export sealing

NPS-610DEC9923C8

The IIFE at the end of the module executes at import time, iterating over all own property names of exports, invoking getters, and redefining them as non-configurable, non-writable frozen values before calling Object.freeze(exports). While this pattern is a defensive measure common in library bundles (here likely to fix circular-require semantics), it is a top-level side effect that mutates the module namespace and can break consumers relying on live bindings or monkey-patching. Any module that runs code on import deserves scrutiny, though no exfiltration or command execution is present.

v4/mini/schemas.cjs
low

Dynamic getter invocation from exports

NPS-CED5E7F482FF

The sealing IIFE calls desc.get() on every configurable getter export. If any export were defined as a getter with side effects, those side effects would be triggered at import time. In this file the getters map to plain schema functions, so no malicious behavior occurs, but the pattern of invoking accessors over the whole exports object is unusual and would be a useful camouflage for lazily triggered payloads in a tampered package.

v4/mini/schemas.cjs

Files reviewed

FileVerdictWhat the reviewer saw
v4/core/checks.cjs critical This is the legitimate zod v4 validation library's checks module; no exfiltration, credential harvesting, shell spawning, network calls, install-time hooks, or obfuscated payloads are present, though it uses dynamic getter evaluation and RegExp construction patterns that would be concerning if the package were tampered with.
v4/core/doc.cjs critical The Doc class dynamically compiles and executes arbitrary JavaScript via the Function constructor using content, argument names, and closed-over values, enabling code injection/RCE if any of these are influenced by untrusted input.
compile.cjs medium This is a legitimate zod compiler side-effect module that performs global monkey-patching and relies on a dynamic code compiler, but contains no exfiltration, credential harvesting, network access, process spawning, or other overtly malicious patterns.
src/compile.ts medium This module is not overtly malicious and contains no exfiltration, credential harvesting, shell execution, or network access, but it performs process-wide global monkey-patching and triggers dynamic JIT code generation at parse time via a side-effect import, which warrants caution.
src/v4/core/compile.ts medium This is a legitimate Zod AOT compiler module whose only notable security-relevant behavior is deliberate new Function code generation (with explicit source-injection guards) plus invocation of user-supplied schema callbacks; no exfiltration, credential harvesting, network, process, or filesystem activity was found.
src/v4/core/doc.ts medium The file implements a code-generation utility that uses new Function for dynamic evaluation; no exfiltration, credential harvesting, process spawning, or network activity was detected, but dynamic code execution warrants review of how Doc content is populated.
v3/external.cjs medium The file is a standard Zod CommonJS re-export shim with an additional export-sealing IIFE that mutates and freezes exports at import time; no exfiltration, credential harvesting, obfuscation, or dynamic code execution was found, but the runtime export mutation is worth noting.
v4/core/compile.cjs medium This is a legitimate Zod AOT compiler module that intentionally uses new Function to emit fast-path validators from schema definitions; the dynamic code generation and invocation of user callbacks are inherent to its purpose, but they represent the main security-relevant surface and require the existing escaping/type backstops to remain sound.
v4/core/compile.js medium This is a legitimate Zod schema compiler that relies on dynamic code generation via new Function; the main security concern is the inherent risk of codegen-based execution and string interpolation of schema values into generated source, though mitigation guards are present.
v4/core/core.js medium No direct malicious behavior (no exfiltration, eval, shells, or credential theft) was found, but the module exposes an undocumented global postProcessor hook invoked on every schema construction and mutates global Error/globalThis state at import and runtime, which warrants caution.
v4/core/doc.js medium The code contains dynamic code execution via the Function constructor, which is a potential security risk if untrusted input can reach the write method.
v4/core/util.cjs medium This is legitimate Zod v4 utility code (schema manipulation, lazy property installation, encoding helpers); it contains no exfiltration, credential harvesting, backdoors, or process/network abuse, though it uses new Function for a capability probe and Math.random() for string generation, both non-malicious but worth noting.
v4/mini/schemas.cjs medium This is the legitimate Zod Mini schema definition file; the only notable behavior is an import-time IIFE that freezes/seals exports, which is a defensive pattern rather than a malicious one, so the file is not a security risk but does contain non-trivial top-level side effects.
compile.js safe No malicious patterns detected; the file only installs an internal compile-time optimization shim with no network, filesystem, process, or obfuscation behavior.
index.cjs safe No malicious patterns detected
index.js safe Cleared by Jev triage; no further analysis needed
locales/index.cjs safe This is a standard TypeScript-generated CommonJS re-export file that seals exports; no malicious patterns detected.
locales/index.js safe Cleared by Jev triage; no further analysis needed
mini/index.cjs safe No malicious patterns detected; the file contains standard TypeScript/CommonJS interop helpers and a defensive export-sealing routine.
mini/index.js safe Cleared by Jev triage; no further analysis needed
src/index.ts safe Cleared by Jev triage; no further analysis needed
src/locales/index.ts safe Cleared by Jev triage; no further analysis needed
src/mini/index.ts safe Cleared by Jev triage; no further analysis needed
src/v3/ZodError.ts safe This is the legitimate Zod error-handling module; no malicious patterns, network calls, credential access, dynamic execution, or install-time behavior were detected.
src/v3/benchmarks/datetime.ts safe Cleared by Jev triage; no further analysis needed
Show 350 more files
FileVerdictWhat the reviewer saw
src/v3/benchmarks/discriminatedUnion.ts safe Cleared by Jev triage; no further analysis needed
src/v3/benchmarks/index.ts safe No malicious patterns detected; the file is a standard benchmark runner that reads CLI arguments and runs in-memory benchmarks without network, filesystem, or process-spawning operations.
src/v3/benchmarks/ipv4.ts safe Cleared by Jev triage; no further analysis needed
src/v3/benchmarks/object.ts safe Cleared by Jev triage; no further analysis needed
src/v3/benchmarks/primitives.ts safe Cleared by Jev triage; no further analysis needed
src/v3/benchmarks/realworld.ts safe No malicious patterns detected; the code is a standard Zod validation benchmark with no network, filesystem, process, or obfuscated behavior.
src/v3/benchmarks/string.ts safe Cleared by Jev triage; no further analysis needed
src/v3/benchmarks/union.ts safe Cleared by Jev triage; no further analysis needed
src/v3/errors.ts safe Cleared by Jev triage; no further analysis needed
src/v3/external.ts safe Cleared by Jev triage; no further analysis needed
src/v3/helpers/enumUtil.ts safe Cleared by Jev triage; no further analysis needed
src/v3/helpers/errorUtil.ts safe Cleared by Jev triage; no further analysis needed
src/v3/helpers/parseUtil.ts safe Cleared by Jev triage; no further analysis needed
src/v3/helpers/partialUtil.ts safe Cleared by Jev triage; no further analysis needed
src/v3/helpers/typeAliases.ts safe Cleared by Jev triage; no further analysis needed
src/v3/helpers/util.ts safe Cleared by Jev triage; no further analysis needed
src/v3/index.ts safe Cleared by Jev triage; no further analysis needed
src/v3/locales/en.ts safe Cleared by Jev triage; no further analysis needed
src/v3/standard-schema.ts safe Cleared by Jev triage; no further analysis needed
src/v4-mini/index.ts safe Cleared by Jev triage; no further analysis needed
src/v4/classic/checks.ts safe Cleared by Jev triage; no further analysis needed
src/v4/classic/coerce.ts safe Cleared by Jev triage; no further analysis needed
src/v4/classic/compat.ts safe Cleared by Jev triage; no further analysis needed
src/v4/classic/deep-partial.ts safe Cleared by Jev triage; no further analysis needed
src/v4/classic/errors.ts safe No malicious patterns detected; the code only implements error handling and prototype-based lazy method installation for Zod validation errors.
src/v4/classic/external.ts safe Cleared by Jev triage; no further analysis needed
src/v4/classic/from-json-schema.ts safe The file is a legitimate JSON Schema to Zod converter with no network, filesystem, process-spawning, credential-harvesting, or dynamic-code-execution behavior; minor ReDoS considerations from user-supplied regex patterns are inherent to JSON Schema.
src/v4/classic/in-out.ts safe Cleared by Jev triage; no further analysis needed
src/v4/classic/index.ts safe Cleared by Jev triage; no further analysis needed
src/v4/classic/iso.ts safe Cleared by Jev triage; no further analysis needed
src/v4/classic/parse.ts safe Cleared by Jev triage; no further analysis needed
src/v4/core/api.ts safe Cleared by Jev triage; no further analysis needed
src/v4/core/checks.ts safe Cleared by Jev triage; no further analysis needed
src/v4/core/core.ts safe No malicious patterns detected; the code is part of Zod's core constructor logic with no data exfiltration, credential harvesting, dynamic code execution, or process spawning.
src/v4/core/errors.ts safe No malicious patterns detected; the file contains only type definitions and error-formatting utilities with explicit prototype-pollution hardening, no network, filesystem, process, or dynamic execution behavior.
src/v4/core/index.ts safe Cleared by Jev triage; no further analysis needed
src/v4/core/json-schema-generator.ts safe Cleared by Jev triage; no further analysis needed
src/v4/core/json-schema-processors.ts safe Cleared by Jev triage; no further analysis needed
src/v4/core/json-schema.ts safe Cleared by Jev triage; no further analysis needed
src/v4/core/memoizer.ts safe The TypeScript memoizer implements schema parsing cycle detection and caching with no network, filesystem, process, or dynamic code execution patterns.
src/v4/core/parse.ts safe Cleared by Jev triage; no further analysis needed
src/v4/core/regexes.ts safe No malicious patterns detected; the file only defines regexes and regex-builder helpers for validation purposes.
src/v4/core/registries.ts safe No malicious patterns detected; the code implements a Zod metadata registry with type utilities and a global registry singleton, with no exfiltration, credential harvesting, obfuscation, process spawning, or other red flags.
src/v4/core/standard-schema.ts safe Cleared by Jev triage; no further analysis needed
src/v4/core/to-json-schema.ts safe No malicious patterns detected; this is a legitimate Zod v4 JSON Schema conversion utility with no network, filesystem, process, or dynamic code execution activity.
src/v4/core/util.ts safe This is a utility/type-definitions module from a Zod-like validation library; no malicious patterns such as data exfiltration, credential harvesting, obfuscated payloads, backdoors, or process spawning were detected, with only a benign eval-capability feature-detection probe present.
src/v4/core/versions.ts safe Cleared by Jev triage; no further analysis needed
src/v4/core/visit.ts safe Cleared by Jev triage; no further analysis needed
src/v4/core/zsf.ts safe Cleared by Jev triage; no further analysis needed
src/v4/index.ts safe Cleared by Jev triage; no further analysis needed
src/v4/locales/ar.ts safe Cleared by Jev triage; no further analysis needed
src/v4/locales/az.ts safe Cleared by Jev triage; no further analysis needed
src/v4/locales/be.ts safe Cleared by Jev triage; no further analysis needed
src/v4/locales/bg.ts safe Cleared by Jev triage; no further analysis needed
src/v4/locales/bn.ts safe Cleared by Jev triage; no further analysis needed
src/v4/locales/ca.ts safe Cleared by Jev triage; no further analysis needed
src/v4/locales/ckb.ts safe Cleared by Jev triage; no further analysis needed
src/v4/locales/cs.ts safe Cleared by Jev triage; no further analysis needed
src/v4/locales/da.ts safe Cleared by Jev triage; no further analysis needed
src/v4/locales/de.ts safe Cleared by Jev triage; no further analysis needed
src/v4/locales/el.ts safe Cleared by Jev triage; no further analysis needed
src/v4/locales/en.ts safe Cleared by Jev triage; no further analysis needed
src/v4/locales/eo.ts safe Cleared by Jev triage; no further analysis needed
src/v4/locales/es.ts safe Cleared by Jev triage; no further analysis needed
src/v4/locales/fa.ts safe Cleared by Jev triage; no further analysis needed
src/v4/locales/fi.ts safe Cleared by Jev triage; no further analysis needed
src/v4/locales/fr-CA.ts safe Cleared by Jev triage; no further analysis needed
src/v4/locales/fr.ts safe Cleared by Jev triage; no further analysis needed
src/v4/locales/gu.ts safe Cleared by Jev triage; no further analysis needed
src/v4/locales/he.ts safe Cleared by Jev triage; no further analysis needed
src/v4/locales/hi.ts safe Cleared by Jev triage; no further analysis needed
src/v4/locales/hr.ts safe Cleared by Jev triage; no further analysis needed
src/v4/locales/hu.ts safe Cleared by Jev triage; no further analysis needed
src/v4/locales/hy.ts safe Cleared by Jev triage; no further analysis needed
src/v4/locales/id.ts safe Cleared by Jev triage; no further analysis needed
src/v4/locales/index.ts safe Cleared by Jev triage; no further analysis needed
src/v4/locales/is.ts safe Cleared by Jev triage; no further analysis needed
src/v4/locales/it.ts safe Cleared by Jev triage; no further analysis needed
src/v4/locales/ja.ts safe Cleared by Jev triage; no further analysis needed
src/v4/locales/ka.ts safe Cleared by Jev triage; no further analysis needed
src/v4/locales/kh.ts safe Cleared by Jev triage; no further analysis needed
src/v4/locales/km.ts safe Cleared by Jev triage; no further analysis needed
src/v4/locales/kn.ts safe Cleared by Jev triage; no further analysis needed
src/v4/locales/ko.ts safe Cleared by Jev triage; no further analysis needed
src/v4/locales/lt.ts safe Cleared by Jev triage; no further analysis needed
src/v4/locales/mk.ts safe Cleared by Jev triage; no further analysis needed
src/v4/locales/ms.ts safe Cleared by Jev triage; no further analysis needed
src/v4/locales/ne.ts safe Cleared by Jev triage; no further analysis needed
src/v4/locales/nl.ts safe Cleared by Jev triage; no further analysis needed
src/v4/locales/nn.ts safe Cleared by Jev triage; no further analysis needed
src/v4/locales/no.ts safe Cleared by Jev triage; no further analysis needed
src/v4/locales/ota.ts safe Cleared by Jev triage; no further analysis needed
src/v4/locales/pl.ts safe Cleared by Jev triage; no further analysis needed
src/v4/locales/ps.ts safe Cleared by Jev triage; no further analysis needed
src/v4/locales/pt-BR.ts safe Cleared by Jev triage; no further analysis needed
src/v4/locales/pt.ts safe Cleared by Jev triage; no further analysis needed
src/v4/locales/ro.ts safe Cleared by Jev triage; no further analysis needed
src/v4/locales/ru.ts safe Cleared by Jev triage; no further analysis needed
src/v4/locales/sk.ts safe Cleared by Jev triage; no further analysis needed
src/v4/locales/sl.ts safe Cleared by Jev triage; no further analysis needed
src/v4/locales/sv.ts safe Cleared by Jev triage; no further analysis needed
src/v4/locales/ta.ts safe Cleared by Jev triage; no further analysis needed
src/v4/locales/tg.ts safe Cleared by Jev triage; no further analysis needed
src/v4/locales/th.ts safe Cleared by Jev triage; no further analysis needed
src/v4/locales/tk.ts safe Cleared by Jev triage; no further analysis needed
src/v4/locales/tr.ts safe Cleared by Jev triage; no further analysis needed
src/v4/locales/ua.ts safe Cleared by Jev triage; no further analysis needed
src/v4/locales/uk.ts safe Cleared by Jev triage; no further analysis needed
src/v4/locales/ur.ts safe Cleared by Jev triage; no further analysis needed
src/v4/locales/uz.ts safe Cleared by Jev triage; no further analysis needed
src/v4/locales/vi.ts safe Cleared by Jev triage; no further analysis needed
src/v4/locales/yo.ts safe Cleared by Jev triage; no further analysis needed
src/v4/locales/zh-CN.ts safe Cleared by Jev triage; no further analysis needed
src/v4/locales/zh-TW.ts safe Cleared by Jev triage; no further analysis needed
src/v4/mini/checks.ts safe Cleared by Jev triage; no further analysis needed
src/v4/mini/coerce.ts safe Cleared by Jev triage; no further analysis needed
src/v4/mini/deep-partial.ts safe Cleared by Jev triage; no further analysis needed
src/v4/mini/external.ts safe Cleared by Jev triage; no further analysis needed
src/v4/mini/in-out.ts safe Cleared by Jev triage; no further analysis needed
src/v4/mini/index.ts safe Cleared by Jev triage; no further analysis needed
src/v4/mini/iso.ts safe Cleared by Jev triage; no further analysis needed
src/v4/mini/parse.ts safe Cleared by Jev triage; no further analysis needed
src/v4/mini/schemas.ts safe Cleared by Jev triage; no further analysis needed
v3/ZodError.cjs safe No malicious patterns detected; this is standard Zod error-handling code with prototype-safe error formatting and export sealing.
v3/ZodError.js safe No malicious patterns detected; the code is a standard Zod error-handling implementation with no exfiltration, obfuscation, dynamic execution, or filesystem/network abuse.
v3/errors.cjs safe No malicious patterns detected; the code only manages error map overrides and seals exports using standard reflection APIs.
v3/errors.js safe Cleared by Jev triage; no further analysis needed
v3/external.js safe Cleared by Jev triage; no further analysis needed
v3/helpers/enumUtil.cjs safe The code only seals and freezes the module's exports object; no malicious patterns detected.
v3/helpers/enumUtil.js safe Cleared by Jev triage; no further analysis needed
v3/helpers/errorUtil.cjs safe No malicious patterns detected; the file only provides simple error message conversion utilities and a defensive export sealing routine that executes at import time but performs no external, filesystem, or process operations.
v3/helpers/errorUtil.js safe No malicious patterns detected
v3/helpers/parseUtil.cjs safe No malicious patterns detected; the file contains only standard Zod library parsing utilities with no network, filesystem, credential, or code-execution activity.
v3/helpers/parseUtil.js safe Cleared by Jev triage; no further analysis needed
v3/helpers/partialUtil.cjs safe The code only seals and freezes the module's exports object; no malicious patterns detected.
v3/helpers/partialUtil.js safe Cleared by Jev triage; no further analysis needed
v3/helpers/typeAliases.cjs safe The code only seals and freezes the module's exports object; no malicious patterns detected.
v3/helpers/typeAliases.js safe Cleared by Jev triage; no further analysis needed
v3/helpers/util.cjs safe No malicious patterns detected; the code is a standard Zod utility module with a benign export-sealing routine.
v3/helpers/util.js safe No malicious patterns detected
v3/index.cjs safe No malicious patterns detected; the code is a standard CommonJS export shim with a sealing mechanism that freezes exports, containing no data exfiltration, credential harvesting, obfuscation, or dynamic code execution.
v3/index.js safe Cleared by Jev triage; no further analysis needed
v3/locales/en.cjs safe Cleared by Jev triage; no further analysis needed
v3/locales/en.js safe Cleared by Jev triage; no further analysis needed
v3/standard-schema.cjs safe The code only seals and freezes the module's exports object; no malicious patterns detected.
v3/standard-schema.js safe Cleared by Jev triage; no further analysis needed
v4-mini/index.cjs safe No malicious patterns detected; the file contains standard TypeScript/CommonJS interop helpers and a defensive export-sealing routine.
v4-mini/index.js safe Cleared by Jev triage; no further analysis needed
v4/classic/checks.cjs safe The file is a standard re-export module that delegates validation checks to ../core/index.cjs and freezes exports; no malicious patterns, obfuscation, network, filesystem, or process activity detected.
v4/classic/checks.js safe Cleared by Jev triage; no further analysis needed
v4/classic/coerce.cjs safe No malicious patterns detected; the file contains standard TypeScript/CommonJS helper functions and Zod schema wrappers with no network, filesystem, process, or obfuscation concerns.
v4/classic/coerce.js safe Cleared by Jev triage; no further analysis needed
v4/classic/compat.cjs safe No malicious patterns detected; the file is a standard TypeScript-generated Zod v3 compatibility shim that only re-exports core utilities and freezes its exports.
v4/classic/compat.js safe Cleared by Jev triage; no further analysis needed
v4/classic/deep-partial.cjs safe No malicious patterns detected; the code is standard TypeScript/CommonJS interop and Zod schema transformation logic with an export-sealing helper.
v4/classic/deep-partial.js safe Cleared by Jev triage; no further analysis needed
v4/classic/errors.cjs safe The file is a standard CommonJS build artifact for Zod error classes; it contains only module initialization, lazy prototype helpers, and export sealing, with no exfiltration, credential harvesting, dynamic code execution, or shell/process spawning.
v4/classic/errors.js safe No malicious patterns detected; the code implements lazy error-method installation for ZodError with no network, filesystem, process, or dynamic-execution behavior.
v4/classic/external.cjs safe This is a standard TypeScript-compiled CommonJS re-export barrel file for the zod library with no malicious patterns detected.
v4/classic/external.js safe Cleared by Jev triage; no further analysis needed
v4/classic/from-json-schema.cjs safe No malicious patterns detected; the file is a legitimate JSON Schema to Zod converter with no network, filesystem, process, or dynamic execution risks.
v4/classic/from-json-schema.js safe No malicious patterns detected; the code is a legitimate JSON Schema to Zod converter with no network, filesystem, process, or dynamic execution activities.
v4/classic/in-out.cjs safe This is a standard Zod library utility module that performs schema traversal and cloning with no malicious patterns detected.
v4/classic/in-out.js safe Cleared by Jev triage; no further analysis needed
v4/classic/index.cjs safe No malicious patterns detected; the code is standard TypeScript-generated CJS interop boilerplate with a safe export-sealing IIFE.
v4/classic/index.js safe Cleared by Jev triage; no further analysis needed
v4/classic/iso.cjs safe This is a standard CommonJS interop wrapper for the Zod ISO schema module with a benign export-sealing IIFE; no malicious patterns were detected.
v4/classic/iso.js safe Cleared by Jev triage; no further analysis needed
v4/classic/parse.cjs safe No malicious patterns detected; the code is standard Zod CJS export wiring with export sealing.
v4/classic/parse.js safe Cleared by Jev triage; no further analysis needed
v4/classic/schemas.cjs safe This is a legitimate Zod schema validation library file with no malicious patterns detected; the top-level code only sets up the module exports and freezes them.
v4/classic/schemas.js safe The file is a standard Zod v4 schema definition module containing only type/validation logic, with no data exfiltration, credential harvesting, obfuscation, network calls, process spawning, or other malicious patterns.
v4/core/api.cjs safe No malicious patterns detected
v4/core/api.js safe Cleared by Jev triage; no further analysis needed
v4/core/checks.js safe This is legitimate zod validation-check implementation code with no malicious patterns detected.
v4/core/core.cjs safe The code is a legitimate Zod v4 core module implementing schema construction internals, with no evidence of exfiltration, credential harvesting, obfuscation, dynamic code execution, process spawning, network activity, or install-time hook abuse.
v4/core/errors.cjs safe No malicious patterns detected; the code is a standard Zod error formatting module with defensive prototype-pollution guards and export freezing, and performs no network, filesystem, process, or dynamic code execution activity.
v4/core/errors.js safe The code is part of the Zod validation library and contains no malicious patterns; the defensive prototype-pollution handling is legitimate security hardening.
v4/core/index.cjs safe This file is a standard TypeScript-compiled CommonJS barrel export with a sealing/freeze routine that remaps getters to concrete values and locks exports; no malicious patterns detected.
v4/core/index.js safe Cleared by Jev triage; no further analysis needed
v4/core/json-schema-generator.cjs safe The file is a legitimate JSON Schema generator wrapper with no malicious patterns such as data exfiltration, credential harvesting, dynamic code execution, or network activity.
v4/core/json-schema-generator.js safe Cleared by Jev triage; no further analysis needed
v4/core/json-schema-processors.cjs safe No malicious patterns detected; the file is a standard Zod JSON Schema generator with TypeScript helper boilerplate and an export-sealing IIFE, with no network, filesystem, or process activity.
v4/core/json-schema-processors.js safe Cleared by Jev triage; no further analysis needed
v4/core/json-schema.cjs safe The code only seals and freezes the module's exports object; no malicious patterns detected.
v4/core/json-schema.js safe Cleared by Jev triage; no further analysis needed
v4/core/memoizer.cjs safe The code is a legitimate Zod library memoizer implementing cycle detection and caching; no malicious patterns such as exfiltration, credential harvesting, obfuscation, backdoors, or network/process activity were detected.
v4/core/memoizer.js safe No malicious patterns detected; the code is a legitimate cycle-detection and memoization utility for Zod schema parsing with no network, filesystem, process, or dynamic execution behavior.
v4/core/parse.cjs safe No malicious patterns detected; the file contains standard Zod schema parsing/encoding logic with no exfiltration, credential harvesting, obfuscation, process spawning, or dynamic code execution.
v4/core/parse.js safe Cleared by Jev triage; no further analysis needed
v4/core/regexes.cjs safe No malicious patterns detected; the file only defines validation regular expressions and helper functions with no network, filesystem, process, credential, or dynamic code execution behavior.
v4/core/regexes.js safe No malicious patterns detected; the file contains only regular expression definitions for validation with no network, filesystem, process, or dynamic code execution activity.
v4/core/registries.cjs safe No malicious patterns detected; the code implements a standard Zod schema registry with global registration and export sealing, containing no network, filesystem, process, or dynamic execution activity.
v4/core/registries.js safe No malicious patterns detected; the code only implements an in-memory schema metadata registry using WeakMap/Map and a shared global registry symbol.
v4/core/standard-schema.cjs safe The code only seals and freezes the module's exports object; no malicious patterns detected.
v4/core/standard-schema.js safe Cleared by Jev triage; no further analysis needed
v4/core/to-json-schema.cjs safe No malicious patterns detected; the file is a JSON Schema conversion module for Zod with only a benign import-time export-sealing IIFE.
v4/core/to-json-schema.js safe This is a legitimate Zod JSON Schema converter with no malicious patterns, network calls, credential access, dynamic code execution, or install-time side effects.
v4/core/util.js safe This is a utility module (appearing to be zod v4 internals) containing no data exfiltration, credential harvesting, shell/process execution, obfuscation, backdoors, or install-time side effects; the only notable items are a benign new Function('') capability probe and non-cryptographic Math.random() usage.
v4/core/versions.cjs safe No malicious patterns detected
v4/core/versions.js safe Cleared by Jev triage; no further analysis needed
v4/core/visit.cjs safe No malicious patterns detected; the file is a legitimate Zod schema traversal utility with no network, filesystem, process, or dynamic code execution activity.
v4/core/visit.js safe Cleared by Jev triage; no further analysis needed
v4/index.cjs safe The file contains only standard TypeScript/CommonJS interop helpers and an export-sealing utility with no malicious patterns detected.
v4/index.js safe Cleared by Jev triage; no further analysis needed
v4/locales/ar.cjs safe No malicious patterns detected; the file is a standard localized error message module for the Zod validation library with no network, filesystem, process, or dynamic execution behavior.
v4/locales/ar.js safe Cleared by Jev triage; no further analysis needed
v4/locales/az.cjs safe This is a standard localization/error message file for the Zod validation library, containing no malicious patterns, network calls, credential access, or dynamic code execution.
v4/locales/az.js safe Cleared by Jev triage; no further analysis needed
v4/locales/be.cjs safe No malicious patterns detected; the file is a standard localization module with only static translation strings and no network, filesystem, or code execution activity.
v4/locales/be.js safe Cleared by Jev triage; no further analysis needed
v4/locales/bg.cjs safe No malicious patterns detected; this is a standard Zod Bulgarian locale file with only localization strings and helper imports.
v4/locales/bg.js safe Cleared by Jev triage; no further analysis needed
v4/locales/bn.cjs safe No malicious patterns detected; this is a standard Zod localization file for Bengali containing only error message translations and safe module interop helpers.
v4/locales/bn.js safe Cleared by Jev triage; no further analysis needed
v4/locales/ca.cjs safe No malicious patterns detected
v4/locales/ca.js safe Cleared by Jev triage; no further analysis needed
v4/locales/ckb.cjs safe The file is a standard localization/translation module for Zod validation errors in Central Kurdish; it contains only static string dictionaries and error-formatting logic with no network, filesystem, process, or dynamic code execution patterns.
v4/locales/ckb.js safe Cleared by Jev triage; no further analysis needed
v4/locales/cs.cjs safe No malicious patterns detected; the file contains standard TypeScript/CommonJS module interop helpers and Czech localization strings for a validation library.
v4/locales/cs.js safe Cleared by Jev triage; no further analysis needed
v4/locales/da.cjs safe No malicious patterns detected; the code is a standard localization file for the Zod validation library.
v4/locales/da.js safe Cleared by Jev triage; no further analysis needed
v4/locales/de.cjs safe This is a standard localization/error message file for the Zod validation library with no malicious patterns detected.
v4/locales/de.js safe Cleared by Jev triage; no further analysis needed
v4/locales/el.cjs safe No malicious patterns detected; the file contains only Greek locale error message definitions for a validation library.
v4/locales/el.js safe Cleared by Jev triage; no further analysis needed
v4/locales/en.cjs safe No malicious patterns detected; the file is a standard TypeScript-compiled locale error message module with no network, filesystem, process execution, or dynamic code evaluation.
v4/locales/en.js safe Cleared by Jev triage; no further analysis needed
v4/locales/eo.cjs safe No malicious patterns detected
v4/locales/eo.js safe Cleared by Jev triage; no further analysis needed
v4/locales/es.cjs safe No malicious patterns detected
v4/locales/es.js safe Cleared by Jev triage; no further analysis needed
v4/locales/fa.cjs safe This is a localization file providing Persian (Farsi) error messages for the Zod validation library, with no malicious patterns detected.
v4/locales/fa.js safe Cleared by Jev triage; no further analysis needed
v4/locales/fi.cjs safe No malicious patterns detected
v4/locales/fi.js safe Cleared by Jev triage; no further analysis needed
v4/locales/fr-CA.cjs safe No malicious patterns detected
v4/locales/fr-CA.js safe Cleared by Jev triage; no further analysis needed
v4/locales/fr.cjs safe No malicious patterns detected; the file contains only standard localization/error message definitions for a validation library.
v4/locales/fr.js safe Cleared by Jev triage; no further analysis needed
v4/locales/gu.cjs safe No malicious patterns detected; the file is a standard locale translation module with only static error message strings and no network, filesystem, process, or dynamic code execution activity.
v4/locales/gu.js safe Cleared by Jev triage; no further analysis needed
v4/locales/he.cjs safe No malicious patterns detected; this is a standard Zod locale/error-message module for Hebrew with only static translations and no network, filesystem, process, or dynamic-execution behavior.
v4/locales/he.js safe Cleared by Jev triage; no further analysis needed
v4/locales/hi.cjs safe No malicious patterns detected
v4/locales/hi.js safe Cleared by Jev triage; no further analysis needed
v4/locales/hr.cjs safe No malicious patterns detected
v4/locales/hr.js safe Cleared by Jev triage; no further analysis needed
v4/locales/hu.cjs safe No malicious patterns detected
v4/locales/hu.js safe Cleared by Jev triage; no further analysis needed
v4/locales/hy.cjs safe No malicious patterns detected; the file is a straightforward localization module for Armenian error messages with no network, filesystem, process execution, or obfuscated code.
v4/locales/hy.js safe Cleared by Jev triage; no further analysis needed
v4/locales/id.cjs safe This is a standard Zod locale/error message file with no malicious patterns detected.
v4/locales/id.js safe Cleared by Jev triage; no further analysis needed
v4/locales/index.cjs safe No malicious patterns detected
v4/locales/index.js safe Cleared by Jev triage; no further analysis needed
v4/locales/is.cjs safe No malicious patterns detected; this is a standard Zod Icelandic locale error message module with no network, filesystem, process, eval, or credential-harvesting behavior.
v4/locales/is.js safe Cleared by Jev triage; no further analysis needed
v4/locales/it.cjs safe This is a standard Zod locale file for Italian error messages with no malicious patterns, network calls, or dynamic code execution beyond TypeScript's own import helpers.
v4/locales/it.js safe Cleared by Jev triage; no further analysis needed
v4/locales/ja.cjs safe No malicious patterns detected; this is a standard localization file for the Zod validation library containing Japanese error messages.
v4/locales/ja.js safe Cleared by Jev triage; no further analysis needed
v4/locales/ka.cjs safe No malicious patterns detected; this is a standard Zod locale file with only localization strings and helper functions.
v4/locales/ka.js safe Cleared by Jev triage; no further analysis needed
v4/locales/kh.cjs safe No malicious patterns detected; this is a simple deprecated locale alias that re-exports the 'km' locale with no external calls or dynamic execution.
v4/locales/kh.js safe Cleared by Jev triage; no further analysis needed
v4/locales/km.cjs safe No malicious patterns detected
v4/locales/km.js safe Cleared by Jev triage; no further analysis needed
v4/locales/kn.cjs safe No malicious patterns detected; the file is a standard localization module for validation error messages with only benign imports and pure message-formatting logic.
v4/locales/kn.js safe Cleared by Jev triage; no further analysis needed
v4/locales/ko.cjs safe This is a legitimate Korean locale file for the Zod validation library containing only translation strings and error message formatting logic with no malicious patterns.
v4/locales/ko.js safe Cleared by Jev triage; no further analysis needed
v4/locales/lt.cjs safe This is a legitimate Lithuanian locale/translation file for a validation library with no malicious patterns detected.
v4/locales/lt.js safe Cleared by Jev triage; no further analysis needed
v4/locales/mk.cjs safe This is a benign localization file for the Zod validation library containing only static Macedonian error message strings, with no malicious patterns detected.
v4/locales/mk.js safe Cleared by Jev triage; no further analysis needed
v4/locales/ms.cjs safe This file is a standard localization module for the Zod validation library containing only static error message translations and no malicious patterns.
v4/locales/ms.js safe Cleared by Jev triage; no further analysis needed
v4/locales/ne.cjs safe This is a localization module for the Zod validation library containing only static error message strings in Nepali; no malicious patterns, network activity, credential access, dynamic execution, or suspicious processes were detected.
v4/locales/ne.js safe Cleared by Jev triage; no further analysis needed
v4/locales/nl.cjs safe No malicious patterns detected
v4/locales/nl.js safe Cleared by Jev triage; no further analysis needed
v4/locales/nn.cjs safe No malicious patterns detected
v4/locales/nn.js safe Cleared by Jev triage; no further analysis needed
v4/locales/no.cjs safe No malicious patterns detected; this is a legitimate localization file for the Zod validation library containing Norwegian error messages.
v4/locales/no.js safe Cleared by Jev triage; no further analysis needed
v4/locales/ota.cjs safe No malicious patterns detected
v4/locales/ota.js safe Cleared by Jev triage; no further analysis needed
v4/locales/pl.cjs safe This is a standard localization file for the Zod validation library containing only Polish error message translations with no malicious patterns.
v4/locales/pl.js safe Cleared by Jev triage; no further analysis needed
v4/locales/ps.cjs safe This is a Zod Pashto locale file containing only error message translations and TypeScript helper boilerplate, with no malicious patterns detected.
v4/locales/ps.js safe Cleared by Jev triage; no further analysis needed
v4/locales/pt-BR.cjs safe No malicious patterns detected; this is a standard localization file for error messages with only TypeScript helper boilerplate and string translations.
v4/locales/pt-BR.js safe Cleared by Jev triage; no further analysis needed
v4/locales/pt.cjs safe The file is a Portuguese locale definition for the Zod validation library containing only static translation strings and error formatting logic, with no network, filesystem, process, or dynamic code execution activity.
v4/locales/pt.js safe Cleared by Jev triage; no further analysis needed
v4/locales/ro.cjs safe This file is a Zod library Romanian locale definition containing only translation strings and error message formatting logic; no malicious patterns detected.
v4/locales/ro.js safe Cleared by Jev triage; no further analysis needed
v4/locales/ru.cjs safe This is a standard Zod locale file containing only Russian translation strings and pluralization logic with no malicious patterns.
v4/locales/ru.js safe Cleared by Jev triage; no further analysis needed
v4/locales/sk.cjs safe No malicious patterns detected; file is a standard localization module for the Zod validation library with only static Slovak error messages and no dynamic execution, network, filesystem, or process activity.
v4/locales/sk.js safe Cleared by Jev triage; no further analysis needed
v4/locales/sl.cjs safe No malicious patterns detected; the file is a standard localization module for the Zod validation library that only contains translation strings and error formatting logic.
v4/locales/sl.js safe Cleared by Jev triage; no further analysis needed
v4/locales/sv.cjs safe No malicious patterns detected; the file contains only standard Swedish localization strings and error message formatting logic for a validation library.
v4/locales/sv.js safe Cleared by Jev triage; no further analysis needed
v4/locales/ta.cjs safe No malicious patterns detected; the file contains only TypeScript/CommonJS interop helpers and Tamil locale error messages for a validation library.
v4/locales/ta.js safe Cleared by Jev triage; no further analysis needed
v4/locales/tg.cjs safe This is a legitimate Zod localization file for Tajik containing only static error message strings and standard TypeScript CommonJS interop helpers, with no network, filesystem, process, or dynamic execution activity.
v4/locales/tg.js safe Cleared by Jev triage; no further analysis needed
v4/locales/th.cjs safe No malicious patterns detected; this is a standard Zod Thai locale error translation module with only static data and no network, file system, or process operations.
v4/locales/th.js safe Cleared by Jev triage; no further analysis needed
v4/locales/tk.cjs safe This is a standard localization/translation file for validation error messages with no malicious patterns, network activity, or dynamic code execution.
v4/locales/tk.js safe Cleared by Jev triage; no further analysis needed
v4/locales/tr.cjs safe No malicious patterns detected in the locale file; it contains only TypeScript helper functions and Turkish error message definitions for a validation library.
v4/locales/tr.js safe Cleared by Jev triage; no further analysis needed
v4/locales/ua.cjs safe No malicious patterns detected; the code is a simple deprecated alias to the Ukrainian locale module.
v4/locales/ua.js safe Cleared by Jev triage; no further analysis needed
v4/locales/uk.cjs safe This is a legitimate Zod locale error message file for Ukrainian with no malicious patterns detected.
v4/locales/uk.js safe Cleared by Jev triage; no further analysis needed
v4/locales/ur.cjs safe This file contains only localization/error message strings for the Urdu locale of the Zod validation library and exhibits no malicious behavior, network access, credential harvesting, or dynamic code execution.
v4/locales/ur.js safe Cleared by Jev triage; no further analysis needed
v4/locales/uz.cjs safe No malicious patterns detected; this is a standard locale error message file for the Zod validation library.
v4/locales/uz.js safe Cleared by Jev triage; no further analysis needed
v4/locales/vi.cjs safe No malicious patterns detected
v4/locales/vi.js safe Cleared by Jev triage; no further analysis needed
v4/locales/yo.cjs safe No malicious patterns detected; the file is a standard Zod locale definition with no network, filesystem, or dynamic code execution activity.
v4/locales/yo.js safe Cleared by Jev triage; no further analysis needed
v4/locales/zh-CN.cjs safe This is a legitimate Zod locale file for Simplified Chinese error messages, containing only TypeScript-compiled helper boilerplate and pure translation/formatting logic with no malicious patterns.
v4/locales/zh-CN.js safe Cleared by Jev triage; no further analysis needed
v4/locales/zh-TW.cjs safe No malicious patterns detected; this is a legitimate localization/error message file for the Zod validation library.
v4/locales/zh-TW.js safe Cleared by Jev triage; no further analysis needed
v4/mini/checks.cjs safe This file is a standard re-export module for a validation library; it contains no malicious patterns, network activity, process execution, or dynamic code evaluation.
v4/mini/checks.js safe The file simply re-exports validation functions from a relative module with no suspicious behavior.
v4/mini/coerce.cjs safe No malicious patterns detected; the code is standard TypeScript-compiled CommonJS module bindings with a harmless export-sealing IIFE.
v4/mini/coerce.js safe Cleared by Jev triage; no further analysis needed
v4/mini/deep-partial.cjs safe The file is a standard TypeScript-to-CommonJS compilation output implementing a deepPartial utility for Zod schemas with no malicious patterns; the only import-time code freezes exports, which is harmless.
v4/mini/deep-partial.js safe Cleared by Jev triage; no further analysis needed
v4/mini/external.cjs safe This is standard TypeScript/CommonJS module re-export boilerplate for the Zod validation library; no malicious patterns detected.
v4/mini/external.js safe Cleared by Jev triage; no further analysis needed
v4/mini/in-out.cjs safe The file contains standard TypeScript helper functions for Zod schema input/output handling and an export sealing routine, with no malicious patterns such as data exfiltration, credential harvesting, obfuscation, dynamic code execution, or process spawning.
v4/mini/in-out.js safe Cleared by Jev triage; no further analysis needed
v4/mini/index.cjs safe No malicious patterns detected; the code is a standard CommonJS interop helper with export sealing and contains no data exfiltration, obfuscation, or dynamic code execution.
v4/mini/index.js safe Cleared by Jev triage; no further analysis needed
v4/mini/iso.cjs safe Legitimate Zod Mini ISO date/time validation module with no malicious patterns detected
v4/mini/iso.js safe No malicious patterns detected; the file only defines Zod Mini ISO validation schemas using internal imports and constructors.
v4/mini/parse.cjs safe No malicious patterns detected; the only notable behavior is a benign import-time export-sealing routine with no exfiltration, credential harvesting, obfuscation, or network/process/file-system activity.
v4/mini/parse.js safe Cleared by Jev triage; no further analysis needed
v4/mini/schemas.js safe No malicious patterns detected in the Zod Mini schema definitions; all code is legitimate schema/validation logic with no exfiltration, dynamic execution, process spawning, or credential access.

Affected version ranges

1 of 4 scanned versions of zod are flagged: 4.6.5 (critical). The latest scanned version, 4.6.5, is critical risk. Only versions we have scanned are listed; unscanned versions between them are not covered.

3.22.44.6.5
VersionsVerdictCountRangeTop findings
4.6.5 Critical 1 4.6.5 Dynamic code execution; Dynamic code execution via new Function
3.25.76 โ€“ 4.1.13 Needs review 2 >=3.25.76 <=4.1.13 Dynamic code execution; Dynamic code execution via Function constructor
3.23.8 Not scanned 1 3.23.8
3.22.4 No issues 1 3.22.4

Flagged files across versions

  • critical v4/core/checks.cjs: present in 4.6.5
  • critical v4/core/doc.cjs (Dynamic code execution) NPS-9534A8F558A8: present in 4.6.5

Full list, including published versions not scanned yet: version ranges API.

Scanned versions of zod

VersionVerdictFilesScanned
4.6.5 Critical risk 375 Oct 6, 2026
4.1.13 Needs review 298 Oct 4, 2026
3.25.76 Needs review 271 Oct 4, 2026
3.22.4 No issues 18 Oct 4, 2026

Frequently asked questions

Is zod safe to use?

zod@4.6.5 has 1 critical, 3 high, 12 medium, 46 low severity findings, including behavior that is dangerous or likely malicious. Do not install it without reviewing the findings.

Does zod contain malware?

The latest scan of zod (4.6.5) flagged critical behavior consistent with malicious or dangerous code. See the findings on this page for the exact files and lines.

How was zod checked?

Togoder Security downloaded the published npm package and had an AI model read its 375 source files, looking for install scripts, credential access, network exfiltration, obfuscation, backdoors and crypto-wallet theft. The results are cached by file hash and shown here.

How do I scan zod together with the rest of my dependencies?

Upload your lockfile at https://security.togoder.click/scan or call the API documented at https://security.togoder.click/api-docs. Files that have already been scanned, like the ones in zod@4.6.5, cost nothing.

Related security reports