Advisories for Npm/@Orpc/Zod package

2026

@orpc/zod: Prototype injection in smart coercion

ZodSmartCoercionPlugin and experimental_ZodSmartCoercionPlugin mishandle object keys that name Object.prototype members. Both coerce request input before validation, so any client that can reach a procedure whose input schema contains an object or a record can: replace the prototype of the coerced input object, and make a request fail with an unhandled TypeError by sending a key such as constructor. This is the same class of bug as GHSA-4h5r-cv8j-4456 in @orpc/json-schema, in …