TavernKeeper Scan Report

bmen25124/SillyTavern-Flowchart

Commit b7c091b Reviewed

No material or immediate-danger concern was identified in this review.

This advisory report describes what the named tools and contextual reviewer found at one exact commit. Unknown or unobserved behavior may still exist.

0 immediate danger 0 material 52 low

What this review found

No material or immediate-danger item was identified.

Minor cautions

Dependency advisory GHSA-4x5r-pxfx-6jf8 applies

Minor caution · low confidence

A dependency advisory was flagged, but the specific affected package cannot be identified from the provided evidence. This project is a browser-based SillyTavern extension that ships as a bundled file, so most dependency advisories in build-time tools do not reach end users.

Technical evidence

Scanner reason: OSV-Scanner matched advisory GHSA-4x5r-pxfx-6jf8 to a dependency declared by this repository.

Contextual assessment: The scanner flagged a low-severity advisory for a dependency in file, but package details were removed from the evidence. The project is a browser extension built with webpack; the shipped artifact is a bundle rather than the full node_modules tree. Many lockfile advisories affect dev-only or build-time transitive dependencies with no runtime reachability in the browser context. Without identifying the specific package and version, concrete user harm cannot be established.

Impact: none · Exploitability: unlikely

Developer action: none

Scanner
osv-scanner 2.4.0
Rule
GHSA-4x5r-pxfx-6jf8
File role
production
Source
package-lock.json

Dependency advisory GHSA-fv7c-fp4j-7gwp applies

Minor caution · low confidence

A high-severity advisory was flagged for a dependency, but the affected package cannot be identified from the evidence. Since this is a browser extension that ships a bundled file, the vulnerable code is likely in a build-time tool that does not run for end users.

Technical evidence

Scanner reason: OSV-Scanner matched advisory GHSA-fv7c-fp4j-7gwp to a dependency declared by this repository.

Contextual assessment: The scanner flagged a high-severity advisory but removed package details. The lockfile includes extensive dev dependencies (babel, jest, webpack, sass, ts-loader) whose transitive dependencies commonly carry advisories for server-side or filesystem operations irrelevant to a browser extension runtime. The production dependencies listed are at recent versions. Without the specific package identity, runtime reachability and concrete harm cannot be confirmed.

Impact: low · Exploitability: unlikely

Developer action: none

Scanner
osv-scanner 2.4.0
Rule
GHSA-fv7c-fp4j-7gwp
File role
production
Source
package-lock.json

Dependency advisory GHSA-mh29-5h37-fv8m applies

Minor caution · low confidence

A medium-severity dependency advisory was flagged, but the specific package is unknown. As a browser extension, the vulnerable code likely does not reach end users at runtime.

Technical evidence

Scanner reason: OSV-Scanner matched advisory GHSA-mh29-5h37-fv8m to a dependency declared by this repository.

Contextual assessment: The scanner flagged a medium-severity advisory with package details removed. The project ships as a webpack bundle for a browser-based SillyTavern extension. Without identifying the affected package, whether it is a production or dev dependency, and whether the vulnerable code path is reachable at runtime, no concrete user harm can be established.

Impact: none · Exploitability: unlikely

Developer action: none

Scanner
osv-scanner 2.4.0
Rule
GHSA-mh29-5h37-fv8m
File role
production
Source
package-lock.json

Dependency advisory GHSA-jp2q-39xq-3w4g applies

Minor caution · low confidence

A medium-severity dependency advisory was flagged, but the affected package cannot be identified. The browser extension context limits runtime exposure to most dependency vulnerabilities.

Technical evidence

Scanner reason: OSV-Scanner matched advisory GHSA-jp2q-39xq-3w4g to a dependency declared by this repository.

Contextual assessment: The scanner flagged a medium-severity advisory with package details removed. The lockfile contains both production and dev dependencies; many advisories in npm ecosystems affect build-time tooling. The shipped extension is a browser bundle. Without the specific package identity and version, runtime reachability cannot be determined.

Impact: none · Exploitability: unlikely

Developer action: none

Scanner
osv-scanner 2.4.0
Rule
GHSA-jp2q-39xq-3w4g
File role
production
Source
package-lock.json

Dependency advisory GHSA-7rx3-28cr-v5wh applies

Minor caution · low confidence

A medium-severity dependency advisory was flagged, but the specific package is unknown. The browser extension ships a bundle, limiting runtime exposure.

Technical evidence

Scanner reason: OSV-Scanner matched advisory GHSA-7rx3-28cr-v5wh to a dependency declared by this repository.

Contextual assessment: The scanner flagged a medium-severity advisory with package details removed. The project is a browser-based SillyTavern extension built with webpack. Without identifying the affected package, its dependency category, and runtime reachability, no concrete harm can be established.

Impact: none · Exploitability: unlikely

Developer action: none

Scanner
osv-scanner 2.4.0
Rule
GHSA-7rx3-28cr-v5wh
File role
production
Source
package-lock.json

Dependency advisory GHSA-qj8w-gfj5-8c6v applies

Minor caution · low confidence

A medium-severity dependency advisory was flagged, but the affected package cannot be identified. The browser extension context limits runtime exposure.

Technical evidence

Scanner reason: OSV-Scanner matched advisory GHSA-qj8w-gfj5-8c6v to a dependency declared by this repository.

Contextual assessment: The scanner flagged a medium-severity advisory with package details removed. The lockfile includes many dev-only dependencies whose transitive packages commonly carry advisories. The shipped artifact is a webpack bundle for a browser extension. Without the specific package identity, runtime reachability cannot be determined.

Impact: none · Exploitability: unlikely

Developer action: none

Scanner
osv-scanner 2.4.0
Rule
GHSA-qj8w-gfj5-8c6v
File role
production
Source
package-lock.json

Dependency advisory GHSA-jmr7-xgp7-cmfj applies

Minor caution · low confidence

A high-severity advisory was flagged for a dependency, but the affected package cannot be identified. Since this is a browser extension shipping a bundled file, the vulnerable code is likely in a build-time tool that does not run for end users.

Technical evidence

Scanner reason: OSV-Scanner matched advisory GHSA-jmr7-xgp7-cmfj to a dependency declared by this repository.

Contextual assessment: The scanner flagged a high-severity advisory but removed package details. The lockfile includes extensive dev dependencies (babel, jest, webpack, sass) whose transitive dependencies commonly carry advisories for server-side or filesystem operations. The production dependencies are at recent versions. Without the specific package identity, runtime reachability and concrete harm cannot be confirmed.

Impact: low · Exploitability: unlikely

Developer action: none

Scanner
osv-scanner 2.4.0
Rule
GHSA-jmr7-xgp7-cmfj
File role
production
Source
package-lock.json

Dependency advisory GHSA-8gc5-j5rx-235r applies

Minor caution · low confidence

A high-severity advisory was flagged for a dependency, but the affected package cannot be identified. The browser extension ships a bundle, so the vulnerable code likely does not reach end users at runtime.

Technical evidence

Scanner reason: OSV-Scanner matched advisory GHSA-8gc5-j5rx-235r to a dependency declared by this repository.

Contextual assessment: The scanner flagged a high-severity advisory but removed package details. The project is a browser-based SillyTavern extension built with webpack. The lockfile includes many dev-only build tools whose transitive dependencies commonly carry advisories. Without identifying the specific affected package, its category, and runtime reachability, concrete user harm cannot be established.

Impact: low · Exploitability: unlikely

Developer action: none

Scanner
osv-scanner 2.4.0
Rule
GHSA-8gc5-j5rx-235r
File role
production
Source
package-lock.json

Dependency advisory GHSA-5c6j-r48x-rmvq applies

Minor caution · low confidence

A security scanner found a known vulnerability in one of the libraries this extension uses. However, the scanner did not specify which library, and many of this project's libraries are only used during development, not when the extension actually runs. The risk to users appears low.

Technical evidence

Scanner reason: OSV-Scanner matched advisory GHSA-5c6j-r48x-rmvq to a dependency declared by this repository.

Contextual assessment: Detailed technical wording was omitted by the public report safety filter.

Impact: low · Exploitability: unlikely

Developer action: Review the OSV-scanner report to identify the specific package, then update it if a fixed version is available.

Scanner
osv-scanner 2.4.0
Rule
GHSA-5c6j-r48x-rmvq
File role
production
Source
package-lock.json

Dependency advisory GHSA-9cx6-37pm-9jff applies

Minor caution · low confidence

A security scanner flagged a vulnerable library, but did not specify which one. Since this is a browser extension and many libraries are build-time only, the practical risk is likely low.

Technical evidence

Scanner reason: OSV-Scanner matched advisory GHSA-9cx6-37pm-9jff to a dependency declared by this repository.

Contextual assessment: OSV-scanner matched advisory GHSA-9cx6-37pm-9jff against a dependency in this browser extension's lockfile. Package details were removed from the scanner output, preventing identification of the affected package and version. The lockfile contains a large number of dev-only build dependencies that do not ship to runtime. Without the package identity, runtime reachability cannot be assessed. The browser-extension deployment context limits concrete harm from most common npm advisory classes.

Impact: low · Exploitability: unlikely

Developer action: Identify the flagged package from the full OSV-scanner output and update it if a patched version exists.

Scanner
osv-scanner 2.4.0
Rule
GHSA-9cx6-37pm-9jff
File role
production
Source
package-lock.json

Dependency advisory GHSA-37qj-frw5-hhjh applies

Minor caution · low confidence

A scanner found a vulnerable dependency but did not name it. Because this project runs in a browser and many dependencies are only used during development, the actual risk is likely low.

Technical evidence

Scanner reason: OSV-Scanner matched advisory GHSA-37qj-frw5-hhjh to a dependency declared by this repository.

Contextual assessment: OSV-scanner matched advisory GHSA-37qj-frw5-hhjh against a dependency in this lockfile. The scanner removed package details, so the affected package, its version, and whether it is a production or dev dependency cannot be determined from the supplied evidence. The project runs as a browser extension, which constrains the attack surface for most dependency vulnerabilities. No attacker-controlled input path to the vulnerable code can be confirmed without the package identity.

Impact: low · Exploitability: unlikely

Developer action: Check the full scanner output for the package name and update it if a fix is available.

Scanner
osv-scanner 2.4.0
Rule
GHSA-37qj-frw5-hhjh
File role
production
Source
package-lock.json

Dependency advisory GHSA-v2hh-gcrm-f6hx applies

Minor caution · low confidence

A security scanner flagged a vulnerable library without specifying which one. Since this is a browser extension with many build-only dependencies, the real-world risk is likely low.

Technical evidence

Scanner reason: OSV-Scanner matched advisory GHSA-v2hh-gcrm-f6hx to a dependency declared by this repository.

Contextual assessment: OSV-scanner matched advisory GHSA-v2hh-gcrm-f6hx against a dependency in this lockfile. Package details were stripped from the scanner output, preventing verification of which package and version are affected. The lockfile includes many dev-only build tool dependencies that are not present at runtime. The browser-extension execution context limits the practical impact of most npm advisory types. Runtime reachability cannot be confirmed without the package identity.

Impact: low · Exploitability: unlikely

Developer action: Identify the affected package from the complete scanner report and upgrade if a patched version is available.

Scanner
osv-scanner 2.4.0
Rule
GHSA-v2hh-gcrm-f6hx
File role
production
Source
package-lock.json

Dependency advisory GHSA-m7jm-9gc2-mpf2 applies

Minor caution · low confidence

A scanner found a critically-rated vulnerability in a library used by this extension, but did not specify which library. Because this is a browser extension and many libraries are only used during development, the actual danger to users cannot be confirmed and is likely limited.

Technical evidence

Scanner reason: OSV-Scanner matched advisory GHSA-m7jm-9gc2-mpf2 to a dependency declared by this repository.

Contextual assessment: OSV-scanner matched advisory GHSA-m7jm-9gc2-mpf2 with critical severity against a dependency in this lockfile. The scanner removed package details, so the affected package, its version, and whether it is a production or dev dependency cannot be determined. Although the advisory severity is critical, the project is a browser extension, and many lockfile entries are dev-only build tools. Without the package identity, runtime reachability, attacker input paths, and concrete user harm cannot be verified. Advisory severity alone does not establish immediate danger.

Impact: low · Exploitability: unlikely

Developer action: Prioritize identifying the critically-flagged package from the full scanner output. If it is a production dependency, update it immediately; if it is a dev dependency, update when convenient.

Scanner
osv-scanner 2.4.0
Rule
GHSA-m7jm-9gc2-mpf2
File role
production
Source
package-lock.json

Dependency advisory GHSA-2g4f-4pwh-qvx6 applies

Minor caution · low confidence

A scanner found a medium-severity vulnerability in a library but did not name it. The practical risk for this browser extension is likely low.

Technical evidence

Scanner reason: OSV-Scanner matched advisory GHSA-2g4f-4pwh-qvx6 to a dependency declared by this repository.

Contextual assessment: OSV-scanner matched advisory GHSA-2g4f-4pwh-qvx6 with medium severity against a dependency in this lockfile. Package details were removed from the scanner output, preventing identification of the affected package and version. The project is a browser extension with many dev-only dependencies. Without the package identity, runtime reachability and attacker input paths cannot be assessed. Medium-severity advisories in browser-extension contexts typically present low concrete risk.

Impact: low · Exploitability: unlikely

Developer action: Identify the flagged package from the full scanner report and update it if a fix is available.

Scanner
osv-scanner 2.4.0
Rule
GHSA-2g4f-4pwh-qvx6
File role
production
Source
package-lock.json

Dependency advisory GHSA-v39h-62p7-jpjc applies

Minor caution · low confidence

A scanner flagged a high-severity vulnerability in a library without specifying which one. Since this is a browser extension with many build-only dependencies, the actual risk is likely low.

Technical evidence

Scanner reason: OSV-Scanner matched advisory GHSA-v39h-62p7-jpjc to a dependency declared by this repository.

Contextual assessment: Detailed technical wording was omitted by the public report safety filter.

Impact: low · Exploitability: unlikely

Developer action: Identify the affected package from the complete scanner output and update it if a patched version exists.

Scanner
osv-scanner 2.4.0
Rule
GHSA-v39h-62p7-jpjc
File role
production
Source
package-lock.json

Dependency advisory GHSA-h67p-54hq-rp68 applies

Minor caution · low confidence

A scanner found a medium-severity vulnerability in a library but did not name it. The practical risk for this browser extension is likely low.

Technical evidence

Scanner reason: OSV-Scanner matched advisory GHSA-h67p-54hq-rp68 to a dependency declared by this repository.

Contextual assessment: OSV-scanner matched advisory GHSA-h67p-54hq-rp68 with medium severity against a dependency in this lockfile. Package details were removed from the scanner output, preventing identification of the affected package and version. The project is a browser extension with many dev-only dependencies. Without the package identity, runtime reachability and attacker input paths cannot be assessed. Medium-severity advisories in browser-extension contexts typically present low concrete risk.

Impact: low · Exploitability: unlikely

Developer action: Identify the flagged package from the full scanner report and update it if a fix is available.

Scanner
osv-scanner 2.4.0
Rule
GHSA-h67p-54hq-rp68
File role
production
Source
package-lock.json

Dependency advisory GHSA-q3j6-qgpj-74h6 applies

Minor caution · medium confidence

A flagged library was found in the project's dependency list. This extension runs inside a browser, and the flagged library is most likely a build tool that does not get included in the final product users install. The risk to end users is low.

Technical evidence

Scanner reason: OSV-Scanner matched advisory GHSA-q3j6-qgpj-74h6 to a dependency declared by this repository.

Contextual assessment: This advisory matches a dependency declared in the lockfile of a browser-based SillyTavern extension. The project builds with Babel, Jest, and Webpack (devDependencies), and many high-severity advisories in such lockfiles map to build-tool transitive dependencies that are not shipped to end users. The extension's runtime context is the SillyTavern browser sandbox, which limits the impact of server-side vulnerability classes such as path traversal or command injection. Without the specific package name and version (removed by the scanner), exact runtime reachability cannot be confirmed, but the project's stated purpose and dependency profile indicate this is most likely a build-time or transitive dependency issue with no direct attacker-controlled input path in the shipped extension.

Impact: low · Exploitability: unlikely

Developer action: Run npm audit to identify the specific package and update it if a patched version is available, prioritizing production dependencies over build tools.

Scanner
osv-scanner 2.4.0
Rule
GHSA-q3j6-qgpj-74h6
File role
production
Source
package-lock.json

Dependency advisory GHSA-wf6x-7x77-mvgw applies

Minor caution · medium confidence

A security scanner flagged a library used by this browser extension. Because the extension runs in a browser and the flagged library is likely a development tool not included in the final install, the practical risk is low.

Technical evidence

Scanner reason: OSV-Scanner matched advisory GHSA-wf6x-7x77-mvgw to a dependency declared by this repository.

Contextual assessment: This high-severity advisory was matched against the lockfile of a frontend SillyTavern extension. The project's production dependencies are browser-oriented libraries (CodeMirror, xyflow, handlebars, zod, zustand, html-to-image, fast-xml-parser). High-severity advisories in projects of this shape frequently correspond to transitive dependencies of devDependencies such as Babel or Jest, which are not present in the shipped bundle. The browser runtime context also means vulnerability classes targeting Node.js server environments are not reachable. The scanner removed package details, preventing confirmation of the exact affected package and version.

Impact: low · Exploitability: unlikely

Developer action: Run npm audit to identify the specific package and update it if a patched version is available.

Scanner
osv-scanner 2.4.0
Rule
GHSA-wf6x-7x77-mvgw
File role
production
Source
package-lock.json

Dependency advisory GHSA-gh4j-gqv2-49f6 applies

Minor caution · medium confidence

A scanner found a medium-risk issue in a library used by this project. Since the extension runs in a browser, the practical danger is likely minimal.

Technical evidence

Scanner reason: OSV-Scanner matched advisory GHSA-gh4j-gqv2-49f6 to a dependency declared by this repository.

Contextual assessment: This medium-severity advisory was matched against the lockfile. The project is a browser-based SillyTavern extension whose shipped artifact is a webpack bundle running in the SillyTavern frontend. Medium-severity advisories in such projects commonly affect build-time transitive dependencies or involve vulnerability classes (e.g., ReDoS, prototype pollution in server contexts) that have limited practical impact in a browser extension runtime. Package details were removed by the scanner, so the exact affected package and its position in the dependency tree cannot be confirmed.

Impact: low · Exploitability: unlikely

Developer action: Run npm audit to identify the specific package and update it if convenient.

Scanner
osv-scanner 2.4.0
Rule
GHSA-gh4j-gqv2-49f6
File role
production
Source
package-lock.json

Dependency advisory GHSA-23c5-xmqv-rm74 applies

Minor caution · medium confidence

A scanner flagged a library in this project's dependency list. The extension runs in a browser, and the flagged library is probably a development tool not shipped to users, so the risk is low.

Technical evidence

Scanner reason: OSV-Scanner matched advisory GHSA-23c5-xmqv-rm74 to a dependency declared by this repository.

Contextual assessment: This high-severity advisory was matched against the lockfile of a browser-based SillyTavern extension. The project uses Babel, Jest, and Webpack as devDependencies, and high-severity advisories in such lockfiles frequently map to transitive dependencies of these build tools. The shipped extension is a browser bundle, so Node.js server-side vulnerability classes are not reachable at runtime. The scanner removed package details, preventing exact identification of the affected package and confirmation of whether it is a production or development dependency.

Impact: low · Exploitability: unlikely

Developer action: Run npm audit to identify the specific package and update it if a patched version is available.

Scanner
osv-scanner 2.4.0
Rule
GHSA-23c5-xmqv-rm74
File role
production
Source
package-lock.json

Dependency advisory GHSA-3jxr-9vmj-r5cp applies

Minor caution · medium confidence

A scanner found a high-risk flag on a library in this project. Because the extension runs in a browser and the library is likely a build-time tool, the actual risk to users is low.

Technical evidence

Scanner reason: OSV-Scanner matched advisory GHSA-3jxr-9vmj-r5cp to a dependency declared by this repository.

Contextual assessment: This high-severity advisory was matched against the lockfile. The project is a frontend SillyTavern extension that ships a webpack bundle to the browser. High-severity advisories in projects with this dependency profile (Babel, Jest, Webpack devDependencies) commonly correspond to build-tool transitive dependencies not present in the shipped artifact. The browser runtime context limits the impact of server-side vulnerability classes. Package details were removed by the scanner, so the exact affected package and its dependency tree position cannot be confirmed.

Impact: low · Exploitability: unlikely

Developer action: Run npm audit to identify the specific package and update it if a patched version is available.

Scanner
osv-scanner 2.4.0
Rule
GHSA-3jxr-9vmj-r5cp
File role
production
Source
package-lock.json

Dependency advisory GHSA-2w6w-674q-4c4q applies

Minor caution · medium confidence

A scanner flagged a critical issue in a library used by this project. However, this extension runs in a browser, and critical library issues in such projects usually affect build tools that are not included in what users actually install. The practical risk is low, but the developer should verify which package is affected.

Technical evidence

Scanner reason: OSV-Scanner matched advisory GHSA-2w6w-674q-4c4q to a dependency declared by this repository.

Contextual assessment: This critical-severity advisory was matched against the lockfile of a browser-based SillyTavern extension. Critical advisories in Node.js project lockfiles frequently involve packages such as tar, cross-spawn, or similar transitive dependencies of build tooling (node-gyp, npm lifecycle scripts) that are devDependencies and are not included in the shipped browser bundle. The extension's runtime is the SillyTavern browser frontend, where server-side vulnerability classes are not applicable. The scanner removed package details, so the exact affected package cannot be confirmed; however, the project's dependency profile and browser-only runtime strongly suggest this is a build-time dependency issue with no runtime reachability in the shipped extension.

Impact: low · Exploitability: unlikely

Developer action: Run npm audit to identify the specific package. If it is a production dependency, update it immediately. If it is a devDependency, update it when convenient to keep the build environment clean.

Scanner
osv-scanner 2.4.0
Rule
GHSA-2w6w-674q-4c4q
File role
production
Source
package-lock.json

Dependency advisory GHSA-xjpj-3mr7-gcpf applies

Minor caution · medium confidence

A scanner flagged a library in this project. Since the extension runs in a browser and the library is likely a development tool, the risk to users is low.

Technical evidence

Scanner reason: OSV-Scanner matched advisory GHSA-xjpj-3mr7-gcpf to a dependency declared by this repository.

Contextual assessment: This high-severity advisory was matched against the lockfile of a browser-based SillyTavern extension. The project's production dependencies are browser-oriented libraries, and its devDependencies include Babel, Jest, and Webpack. High-severity advisories in such lockfiles commonly map to transitive dependencies of build tools that are not shipped to end users. The browser runtime context limits the impact of server-side vulnerability classes. Package details were removed by the scanner, preventing exact identification.

Impact: low · Exploitability: unlikely

Developer action: Run npm audit to identify the specific package and update it if a patched version is available.

Scanner
osv-scanner 2.4.0
Rule
GHSA-xjpj-3mr7-gcpf
File role
production
Source
package-lock.json

Dependency advisory GHSA-v56q-mh7h-f735 applies

Minor caution · medium confidence

A scanner found a high-risk flag on a library in this project. Because the extension runs in a browser and the library is likely a build-time tool, the actual risk to users is low.

Technical evidence

Scanner reason: OSV-Scanner matched advisory GHSA-v56q-mh7h-f735 to a dependency declared by this repository.

Contextual assessment: This high-severity advisory was matched against the lockfile of a browser-based SillyTavern extension. The project ships a webpack bundle to the SillyTavern browser frontend. High-severity advisories in projects with this dependency profile frequently correspond to build-tool transitive dependencies not present in the shipped artifact. The browser runtime context means server-side vulnerability classes are not reachable. Package details were removed by the scanner, so the exact affected package and its position in the dependency tree cannot be confirmed.

Impact: low · Exploitability: unlikely

Developer action: Run npm audit to identify the specific package and update it if a patched version is available.

Scanner
osv-scanner 2.4.0
Rule
GHSA-v56q-mh7h-f735
File role
production
Source
package-lock.json

Dependency advisory GHSA-7p8r-x3mc-p8w7 applies

Minor caution · medium confidence

A security tool found that this project uses a software library with a known issue. Because this is a browser extension for a local roleplay tool, this issue is unlikely to cause serious harm and is something the developer should update when convenient.

Technical evidence

Scanner reason: OSV-Scanner matched advisory GHSA-7p8r-x3mc-p8w7 to a dependency declared by this repository.

Contextual assessment: The scanner matched a known advisory for a declared dependency. This project is a front-end SillyTavern extension. Vulnerabilities in this context typically affect either build-time devDependencies (which are not shipped to users) or front-end libraries where the user controls the environment and inputs. Typical impacts are XSS or ReDoS, which have limited severity in a local user-controlled roleplay tool. Without specific package details and runtime reachability analysis, this is treated as a minor weakness.

Impact: low · Exploitability: unlikely

Developer action: Update the flagged dependency to a patched version. Verify if the vulnerable code is actually reachable in the extension's runtime.

Scanner
osv-scanner 2.4.0
Rule
GHSA-7p8r-x3mc-p8w7
File role
production
Source
package-lock.json

Dependency advisory GHSA-7r86-cg39-jmmj applies

Minor caution · medium confidence

A security tool found that this project uses a software library with a known issue. Because this is a browser extension for a local roleplay tool, this issue is unlikely to cause serious harm and is something the developer should update when convenient.

Technical evidence

Scanner reason: OSV-Scanner matched advisory GHSA-7r86-cg39-jmmj to a dependency declared by this repository.

Contextual assessment: The scanner matched a known advisory for a declared dependency. This project is a front-end SillyTavern extension. Vulnerabilities in this context typically affect either build-time devDependencies (which are not shipped to users) or front-end libraries where the user controls the environment and inputs. Typical impacts are XSS or ReDoS, which have limited severity in a local user-controlled roleplay tool. Without specific package details and runtime reachability analysis, this is treated as a minor weakness.

Impact: low · Exploitability: unlikely

Developer action: Update the flagged dependency to a patched version. Verify if the vulnerable code is actually reachable in the extension's runtime.

Scanner
osv-scanner 2.4.0
Rule
GHSA-7r86-cg39-jmmj
File role
production
Source
package-lock.json

Dependency advisory GHSA-6g55-p6wh-862q applies

Minor caution · medium confidence

A security tool found that this project uses a software library with a known issue. Because this is a browser extension for a local roleplay tool, this issue is unlikely to cause serious harm and is something the developer should update when convenient.

Technical evidence

Scanner reason: OSV-Scanner matched advisory GHSA-6g55-p6wh-862q to a dependency declared by this repository.

Contextual assessment: The scanner matched a known advisory for a declared dependency. This project is a front-end SillyTavern extension. Vulnerabilities in this context typically affect either build-time devDependencies (which are not shipped to users) or front-end libraries where the user controls the environment and inputs. Typical impacts are XSS or ReDoS, which have limited severity in a local user-controlled roleplay tool. Without specific package details and runtime reachability analysis, this is treated as a minor weakness.

Impact: low · Exploitability: unlikely

Developer action: Update the flagged dependency to a patched version. Verify if the vulnerable code is actually reachable in the extension's runtime.

Scanner
osv-scanner 2.4.0
Rule
GHSA-6g55-p6wh-862q
File role
production
Source
package-lock.json

Dependency advisory GHSA-8fgc-7cc6-rx7x applies

Minor caution · medium confidence

A security tool found that this project uses a software library with a known issue. Because this is a browser extension for a local roleplay tool, this issue is unlikely to cause serious harm and is something the developer should update when convenient.

Technical evidence

Scanner reason: OSV-Scanner matched advisory GHSA-8fgc-7cc6-rx7x to a dependency declared by this repository.

Contextual assessment: The scanner matched a known advisory for a declared dependency. This project is a front-end SillyTavern extension. Vulnerabilities in this context typically affect either build-time devDependencies (which are not shipped to users) or front-end libraries where the user controls the environment and inputs. Typical impacts are XSS or ReDoS, which have limited severity in a local user-controlled roleplay tool. Without specific package details and runtime reachability analysis, this is treated as a minor weakness.

Impact: low · Exploitability: unlikely

Developer action: Update the flagged dependency to a patched version. Verify if the vulnerable code is actually reachable in the extension's runtime.

Scanner
osv-scanner 2.4.0
Rule
GHSA-8fgc-7cc6-rx7x
File role
production
Source
package-lock.json

Dependency advisory GHSA-r28c-9q8g-f849 applies

Minor caution · medium confidence

A security tool found that this project uses a software library with a known issue. Because this is a browser extension for a local roleplay tool, this issue is unlikely to cause serious harm and is something the developer should update when convenient.

Technical evidence

Scanner reason: OSV-Scanner matched advisory GHSA-r28c-9q8g-f849 to a dependency declared by this repository.

Contextual assessment: The scanner matched a known advisory for a declared dependency. This project is a front-end SillyTavern extension. Vulnerabilities in this context typically affect either build-time devDependencies (which are not shipped to users) or front-end libraries where the user controls the environment and inputs. Typical impacts are XSS or ReDoS, which have limited severity in a local user-controlled roleplay tool. Without specific package details and runtime reachability analysis, this is treated as a minor weakness.

Impact: low · Exploitability: unlikely

Developer action: Update the flagged dependency to a patched version. Verify if the vulnerable code is actually reachable in the extension's runtime.

Scanner
osv-scanner 2.4.0
Rule
GHSA-r28c-9q8g-f849
File role
production
Source
package-lock.json

Dependency advisory GHSA-xhpv-hc6g-r9c6 applies

Minor caution · medium confidence

A security tool found that this project uses a software library with a known issue. Because this is a browser extension for a local roleplay tool, this issue is unlikely to cause serious harm and is something the developer should update when convenient.

Technical evidence

Scanner reason: OSV-Scanner matched advisory GHSA-xhpv-hc6g-r9c6 to a dependency declared by this repository.

Contextual assessment: The scanner matched a known advisory for a declared dependency. This project is a front-end SillyTavern extension. Vulnerabilities in this context typically affect either build-time devDependencies (which are not shipped to users) or front-end libraries where the user controls the environment and inputs. Typical impacts are XSS or ReDoS, which have limited severity in a local user-controlled roleplay tool. Without specific package details and runtime reachability analysis, this is treated as a minor weakness.

Impact: low · Exploitability: unlikely

Developer action: Update the flagged dependency to a patched version. Verify if the vulnerable code is actually reachable in the extension's runtime.

Scanner
osv-scanner 2.4.0
Rule
GHSA-xhpv-hc6g-r9c6
File role
production
Source
package-lock.json

Dependency advisory GHSA-xvcm-6775-5m9r applies

Minor caution · medium confidence

A security tool found that this project uses a software library with a known issue. Because this is a browser extension for a local roleplay tool, this issue is unlikely to cause serious harm and is something the developer should update when convenient.

Technical evidence

Scanner reason: OSV-Scanner matched advisory GHSA-xvcm-6775-5m9r to a dependency declared by this repository.

Contextual assessment: The scanner matched a known advisory for a declared dependency. This project is a front-end SillyTavern extension. Vulnerabilities in this context typically affect either build-time devDependencies (which are not shipped to users) or front-end libraries where the user controls the environment and inputs. Typical impacts are XSS or ReDoS, which have limited severity in a local user-controlled roleplay tool. Without specific package details and runtime reachability analysis, this is treated as a minor weakness.

Impact: low · Exploitability: unlikely

Developer action: Update the flagged dependency to a patched version. Verify if the vulnerable code is actually reachable in the extension's runtime.

Scanner
osv-scanner 2.4.0
Rule
GHSA-xvcm-6775-5m9r
File role
production
Source
package-lock.json

Dependency advisory GHSA-3v7f-55p6-f55p applies

Minor caution · medium confidence

A security tool found that this project uses a software library with a known issue. Because this is a browser extension for a local roleplay tool, this issue is unlikely to cause serious harm and is something the developer should update when convenient.

Technical evidence

Scanner reason: OSV-Scanner matched advisory GHSA-3v7f-55p6-f55p to a dependency declared by this repository.

Contextual assessment: The scanner matched a known advisory for a declared dependency. This project is a front-end SillyTavern extension. Vulnerabilities in this context typically affect either build-time devDependencies (which are not shipped to users) or front-end libraries where the user controls the environment and inputs. Typical impacts are XSS or ReDoS, which have limited severity in a local user-controlled roleplay tool. Without specific package details and runtime reachability analysis, this is treated as a minor weakness.

Impact: low · Exploitability: unlikely

Developer action: Update the flagged dependency to a patched version. Verify if the vulnerable code is actually reachable in the extension's runtime.

Scanner
osv-scanner 2.4.0
Rule
GHSA-3v7f-55p6-f55p
File role
production
Source
package-lock.json

Dependency advisory GHSA-3mfm-83xf-c92r applies

Minor caution · low confidence

A scanner flagged a dependency as having a known security issue, but the evidence does not show which package or whether it is actually used when the extension runs. Many flagged packages in this project are likely build tools that never reach the user's browser.

Technical evidence

Scanner reason: OSV-Scanner matched advisory GHSA-3mfm-83xf-c92r to a dependency declared by this repository.

Contextual assessment: OSV-scanner matched a high-severity advisory against a dependency in the lockfile. The provided source context only shows the top-level dependency declarations and the first portion of the lockfile; the specific vulnerable package name, resolved version, and whether it is a production or dev dependency are not visible in the supplied evidence. This project is a browser-based SillyTavern extension built with webpack and babel, so many transitive dependencies are build-time only and are not shipped in the runtime bundle. Without confirmed package identity, version applicability, and runtime reachability, the advisory cannot be elevated beyond a minor weakness.

Impact: low · Exploitability: unlikely

Developer action: Review the OSV-scanner output to identify the specific package, confirm whether it is a dev dependency, and update it if a patched version is available.

Scanner
osv-scanner 2.4.0
Rule
GHSA-3mfm-83xf-c92r
File role
production
Source
package-lock.json

Dependency advisory GHSA-4c8g-83qw-93j6 applies

Minor caution · low confidence

A scanner flagged a dependency, but the evidence does not confirm which package it is or whether it affects the running extension. If it is a build-only tool, it poses no direct risk to users.

Technical evidence

Scanner reason: OSV-Scanner matched advisory GHSA-4c8g-83qw-93j6 to a dependency declared by this repository.

Contextual assessment: OSV-scanner matched a high-severity advisory against a lockfile dependency. The supplied evidence does not include the flagged package name, resolved version, or dependency tier. The project bundles a browser extension via webpack; transitive build-tool dependencies are not part of the shipped runtime. Without confirming the package identity and runtime reachability, this remains a minor weakness.

Impact: low · Exploitability: unlikely

Developer action: Identify the specific package from the scanner output, verify whether it ships at runtime, and update to a patched version if available.

Scanner
osv-scanner 2.4.0
Rule
GHSA-4c8g-83qw-93j6
File role
production
Source
package-lock.json

Dependency advisory GHSA-w5hq-g745-h8pq applies

Minor caution · low confidence

A scanner flagged a dependency with a medium-severity issue, but the evidence does not show which package or whether it is used at runtime. The risk to end users is likely low.

Technical evidence

Scanner reason: OSV-Scanner matched advisory GHSA-w5hq-g745-h8pq to a dependency declared by this repository.

Contextual assessment: OSV-scanner matched a medium-severity advisory against a lockfile dependency. The evidence does not identify the specific package, resolved version, or whether it is a production or dev dependency. Runtime reachability and attacker input control cannot be confirmed from the supplied source context. The project is a browser extension where many transitive dependencies are build-time only.

Impact: low · Exploitability: unlikely

Developer action: Identify the flagged package, confirm runtime usage, and update if a patched version exists.

Scanner
osv-scanner 2.4.0
Rule
GHSA-w5hq-g745-h8pq
File role
production
Source
package-lock.json

Dependency advisory GHSA-f886-m6hf-6m8v applies

Minor caution · low confidence

A scanner flagged a dependency, but the evidence does not confirm which package or whether it runs in the extension. The user-facing risk is likely low.

Technical evidence

Scanner reason: OSV-Scanner matched advisory GHSA-f886-m6hf-6m8v to a dependency declared by this repository.

Contextual assessment: OSV-scanner matched a medium-severity advisory against a lockfile dependency. The specific package name, resolved version, and dependency tier are not present in the supplied evidence. Without confirming runtime reachability and attacker-controlled input paths, this cannot be elevated beyond a minor weakness.

Impact: low · Exploitability: unlikely

Developer action: Identify the flagged package from scanner output, verify whether it ships at runtime, and update if a fix is available.

Scanner
osv-scanner 2.4.0
Rule
GHSA-f886-m6hf-6m8v
File role
production
Source
package-lock.json

Dependency advisory GHSA-fj3w-jwp8-x2g3 applies

Minor caution · low confidence

A low-severity issue was flagged in a dependency the extension uses. The version is recent and the impact is likely minimal, but updating is still good practice.

Technical evidence

Scanner reason: OSV-Scanner matched advisory GHSA-fj3w-jwp8-x2g3 to a dependency declared by this repository.

Contextual assessment: OSV-scanner matched a low-severity advisory, likely against fast-xml-parser which is declared as a production dependency at version ^5.2.5. The advisory severity is low and the declared version is recent. The supplied evidence does not show the exact resolved version or confirm that the vulnerable code path is reachable with attacker-controlled XML input at runtime. Given the low severity and uncertainty, this is a minor weakness.

Impact: low · Exploitability: unlikely

Developer action: Confirm the resolved fast-xml-parser version is at or above the patched version and update if necessary.

Scanner
osv-scanner 2.4.0
Rule
GHSA-fj3w-jwp8-x2g3
File role
production
Source
package-lock.json

Dependency advisory GHSA-qx2v-qp2m-jg93 applies

Minor caution · low confidence

A scanner flagged a dependency with a medium issue, but the evidence does not show which package or whether it runs in the extension. The risk to users is likely low.

Technical evidence

Scanner reason: OSV-Scanner matched advisory GHSA-qx2v-qp2m-jg93 to a dependency declared by this repository.

Contextual assessment: OSV-scanner matched a medium-severity advisory against a lockfile dependency. The evidence does not identify the specific package, resolved version, or dependency tier. Runtime reachability and attacker input control cannot be confirmed. The project is a browser extension where many transitive dependencies are build-time only.

Impact: low · Exploitability: unlikely

Developer action: Identify the flagged package, confirm runtime usage, and update if a patched version exists.

Scanner
osv-scanner 2.4.0
Rule
GHSA-qx2v-qp2m-jg93
File role
production
Source
package-lock.json

Dependency advisory GHSA-52cp-r559-cp3m applies

Minor caution · low confidence

A scanner flagged a dependency with a high-severity label, but the evidence does not confirm which package or whether it is used when the extension runs. If it is a build-only tool, it poses no direct risk to users.

Technical evidence

Scanner reason: OSV-Scanner matched advisory GHSA-52cp-r559-cp3m to a dependency declared by this repository.

Contextual assessment: OSV-scanner matched a high-severity advisory against a lockfile dependency. The supplied evidence does not include the flagged package name, resolved version, or dependency tier. The project bundles a browser extension via webpack; transitive build-tool dependencies are not part of the shipped runtime. Without confirming package identity and runtime reachability, this remains a minor weakness.

Impact: low · Exploitability: unlikely

Developer action: Identify the specific package from scanner output, verify whether it ships at runtime, and update to a patched version if available.

Scanner
osv-scanner 2.4.0
Rule
GHSA-52cp-r559-cp3m
File role
production
Source
package-lock.json

Dependency advisory GHSA-fxqj-rqcc-2cmp applies

Minor caution · low confidence

A scanner flagged a dependency, but the evidence does not confirm which package or whether it runs in the extension. The user-facing risk is likely low.

Technical evidence

Scanner reason: OSV-Scanner matched advisory GHSA-fxqj-rqcc-2cmp to a dependency declared by this repository.

Contextual assessment: OSV-scanner matched a medium-severity advisory against a lockfile dependency. The specific package name, resolved version, and dependency tier are not present in the supplied evidence. Without confirming runtime reachability and attacker-controlled input paths, this cannot be elevated beyond a minor weakness.

Impact: low · Exploitability: unlikely

Developer action: Identify the flagged package from scanner output, verify whether it ships at runtime, and update if a fix is available.

Scanner
osv-scanner 2.4.0
Rule
GHSA-fxqj-rqcc-2cmp
File role
production
Source
package-lock.json

Dependency advisory GHSA-3ppc-4f35-3m26 applies

Minor caution · medium confidence

A security warning was found for a library used by this extension. Because the extension runs on your own computer and you create the content it processes, it is unlikely an attacker could trigger the problem.

Technical evidence

Scanner reason: OSV-Scanner matched advisory GHSA-3ppc-4f35-3m26 to a dependency declared by this repository.

Contextual assessment: A high-severity advisory was matched against a dependency in this client-side SillyTavern extension. The extension runs locally in the user's browser, and its primary inputs are flowcharts the user authors themselves. Without attacker-controlled input reaching the vulnerable code path at runtime, the advisory represents a latent weakness rather than an exploitable vulnerability in this deployment context. The specific package and locked version were not included in the supplied evidence, preventing precise runtime-reachability analysis.

Impact: low · Exploitability: unlikely

Developer action: Update the affected dependency to a patched version when a compatible release is available.

Scanner
osv-scanner 2.4.0
Rule
GHSA-3ppc-4f35-3m26
File role
production
Source
package-lock.json

Dependency advisory GHSA-mh99-v99m-4gvg applies

Minor caution · medium confidence

A security warning was found for a library used by this extension. Since you control what the extension processes and it runs locally, the risk of someone exploiting this is low.

Technical evidence

Scanner reason: OSV-Scanner matched advisory GHSA-mh99-v99m-4gvg to a dependency declared by this repository.

Contextual assessment: A high-severity advisory was matched against a dependency in this browser-based extension. The project processes user-authored flowchart definitions and chat content within the local SillyTavern environment. The advisory's severity reflects worst-case scenarios that typically require attacker-controlled input to reach the vulnerable function. In this context, inputs are primarily user-controlled, limiting runtime reachability. Package details were stripped from the scanner output, so exact version confirmation is not possible from the supplied evidence.

Impact: low · Exploitability: unlikely

Developer action: Update the affected dependency to a patched version when a compatible release is available.

Scanner
osv-scanner 2.4.0
Rule
GHSA-mh99-v99m-4gvg
File role
production
Source
package-lock.json

Dependency advisory GHSA-c2c7-rcm5-vvqj applies

Minor caution · medium confidence

A security warning was found for a library used by this extension. Because the extension runs on your computer and you control its inputs, it is unlikely an attacker could exploit this.

Technical evidence

Scanner reason: OSV-Scanner matched advisory GHSA-c2c7-rcm5-vvqj to a dependency declared by this repository.

Contextual assessment: A high-severity advisory was matched against a dependency in this local browser extension. The extension's data flows are primarily user-driven: the user creates flowcharts, connects nodes, and triggers execution manually or through SillyTavern events. The advisory severity reflects potential impact under attacker-controlled input conditions that are not present in normal use. The scanner removed package details, so the exact vulnerable version and its runtime reachability cannot be confirmed from the supplied evidence alone.

Impact: low · Exploitability: unlikely

Developer action: Update the affected dependency to a patched version when a compatible release is available.

Scanner
osv-scanner 2.4.0
Rule
GHSA-c2c7-rcm5-vvqj
File role
production
Source
package-lock.json

Dependency advisory GHSA-2qvq-rjwj-gvw9 applies

Minor caution · medium confidence

A moderate security warning was found for a library used by this extension. Since you control what the extension processes, the risk is low.

Technical evidence

Scanner reason: OSV-Scanner matched advisory GHSA-2qvq-rjwj-gvw9 to a dependency declared by this repository.

Contextual assessment: A medium-severity advisory was matched against a dependency in this client-side extension. The project operates within the SillyTavern browser environment, processing user-authored flowchart configurations. Medium-severity advisories typically require specific attacker-controlled input to reach the vulnerable code path. In this context, the user is the primary input source, reducing exploitability. Package details were not included in the scanner output.

Impact: low · Exploitability: unlikely

Developer action: Update the affected dependency to a patched version when a compatible release is available.

Scanner
osv-scanner 2.4.0
Rule
GHSA-2qvq-rjwj-gvw9
File role
production
Source
package-lock.json

Dependency advisory GHSA-rgw5-rvv9-x895 applies

Minor caution · medium confidence

A security warning was found for a library used by this extension. Because the extension runs locally and you control its inputs, the risk of exploitation is low.

Technical evidence

Scanner reason: OSV-Scanner matched advisory GHSA-rgw5-rvv9-x895 to a dependency declared by this repository.

Contextual assessment: A high-severity advisory was matched against a dependency in this local browser extension. The extension processes user-authored flowchart data and SillyTavern chat content. While the advisory severity is high, exploitation typically requires attacker-controlled input to reach the vulnerable function. The extension's design requires users to explicitly enable dangerous nodes, and primary data flows are user-controlled. The scanner stripped package details, preventing exact version and reachability confirmation.

Impact: low · Exploitability: unlikely

Developer action: Update the affected dependency to a patched version when a compatible release is available.

Scanner
osv-scanner 2.4.0
Rule
GHSA-rgw5-rvv9-x895
File role
production
Source
package-lock.json
Expected scanner matches (4)

Dependency advisory GHSA-442j-39wm-28r2 applies

Expected behavior · medium confidence

A minor security note was found for a library used by this extension. The issue is low severity and unlikely to cause any real problem in this extension.

Technical evidence

Scanner reason: OSV-Scanner matched advisory GHSA-442j-39wm-28r2 to a dependency declared by this repository.

Contextual assessment: A low-severity advisory was matched against a dependency in this extension. Low-severity advisories often affect development-only toolchains or describe theoretical issues with minimal concrete impact. The extension is a client-side browser application with user-authored inputs. Without evidence that attacker-controlled data reaches the vulnerable code at runtime, and given the low severity rating, this does not represent a material risk in this context.

Impact: none · Exploitability: unlikely

Developer action: none

Scanner
osv-scanner 2.4.0
Rule
GHSA-442j-39wm-28r2
File role
production
Source
package-lock.json

OpenGrep reported tavernkeeper.dynamic-execution.javascript-eval

Expected behavior · high confidence

This is a visual programming block that lets the user write and run their own JavaScript as part of a flow. Running custom code is exactly what the block is for, and the project warns users it is dangerous and requires them to turn on a special toggle before it will run. This is an intended feature, not a hidden threat.

Technical evidence

Scanner reason: OpenGrep matched static-analysis rule tavernkeeper.dynamic-execution.javascript-eval in this repository.

Contextual assessment: The flagged line constructs a function from user-supplied node data and executes it with input, variables, and the SillyTavern context. This is the explicit, stated purpose of the Execute JS Code node in a visual flow editor. The node definition marks itself as dangerous and the project documentation states such nodes only run when the user explicitly enables an Allow Dangerous toggle for a specific flow. The executed code originates from the flow author, not from an external attacker-controlled source, and execution is gated behind a documented user opt-in. No concealed exfiltration, hidden persistence, or obfuscation is present.

Impact: high · Exploitability: plausible

Developer action: none

Scanner
opengrep 1.26.0
Rule
tavernkeeper.dynamic-execution.javascript-eval
File role
production
Source
src/components/nodes/ExecuteJsNode/definition.ts:27

Dependency advisory GHSA-38r7-794h-5758 applies

Expected behavior · medium confidence

A minor security note was found for a library used by this extension. The issue is low severity and unlikely to affect you.

Technical evidence

Scanner reason: OSV-Scanner matched advisory GHSA-38r7-794h-5758 to a dependency declared by this repository.

Contextual assessment: A low-severity advisory was matched against a dependency in this extension. The project is a browser-based SillyTavern extension with user-controlled inputs. Low-severity advisories frequently describe issues with minimal real-world impact or affect development-only dependencies that do not ship to runtime. Without evidence of attacker-controlled input reaching the vulnerable code, this does not represent a material risk.

Impact: none · Exploitability: unlikely

Developer action: none

Scanner
osv-scanner 2.4.0
Rule
GHSA-38r7-794h-5758
File role
production
Source
package-lock.json

OpenGrep reported tavernkeeper.dynamic-execution.javascript-eval

Expected behavior · high confidence

This extension lets users build visual flowcharts that can run custom JavaScript inside an If node. The project clearly warns that this is a dangerous feature and requires the user to turn on an Allow Dangerous switch before it will run. Since the user writes the code themselves and must explicitly enable it, this is intended behavior, not a security problem.

Technical evidence

Scanner reason: OpenGrep matched static-analysis rule tavernkeeper.dynamic-execution.javascript-eval in this repository.

Contextual assessment: The matched construct dynamically constructs a function from condition.code, which is user-authored logic entered into an If node's advanced code editor. This is a core, disclosed feature of a visual flowchart automation extension. The project documentation explicitly labels the If node as dangerous in advanced mode and states such nodes only execute when the user enables the per-flow Allow Dangerous toggle. The code runs locally in the user's own browser extension context, is authored by the user themselves, and is gated behind an explicit opt-in. No concealed execution, exfiltration, or untrusted remote input is present in the supplied evidence.

Impact: none · Exploitability: unlikely

Developer action: none

Scanner
opengrep 1.26.0
Rule
tavernkeeper.dynamic-execution.javascript-eval
File role
production
Source
src/components/nodes/IfNode/definition.ts:87

Related contextual observations

Dependency advisory package identities unavailable across all eight candidates

low risk · low confidence

All eight dependency advisories were flagged with package details removed, making it impossible to determine which packages are affected or whether the vulnerable code reaches end users. The project is a browser extension that ships a bundled file, which limits runtime exposure to most dependency vulnerabilities.

Technical assessment

All eight scanner candidates are dependency advisories from file with package details removed from the evidence. The provided source context shows the top-level package definition with production dependencies (handlebars, fast-xml-parser, zod, zustand, uuid, etc.) at recent versions and extensive dev dependencies (babel, jest, webpack, sass, ts-loader). The project is a browser-based SillyTavern extension built with webpack, meaning the shipped artifact is a bundle rather than the full dependency tree. Without the specific package names and versions for each advisory, it is not possible to determine whether the vulnerable code is in a production dependency with runtime reachability or a dev-only build tool. Most npm ecosystem advisories affecting build tooling transitive dependencies have no runtime reachability in a browser extension context.

Impact: low · Exploitability: unlikely

Developer action: Consider running a dependency audit that preserves package names and versions to identify whether any flagged advisories affect production dependencies with runtime reachability in the shipped browser bundle.

Sources:

Scanner removed package details for all eight dependency advisories, preventing precise runtime reachability analysis

low risk · medium confidence

The scanner hid the specific library names for all eight flags, so it is not possible to say exactly which tools are affected. Based on the project type (a browser extension) and its toolset, the flagged libraries are most likely build tools that do not reach end users. The developer should run npm audit locally to get the full list and update what they can.

Technical assessment

All eight candidates originate from osv-scanner with the explanation that package details were removed. The supplied source context shows only the top-level package.json dependencies and devDependencies, not the full lockfile entries with specific package names, versions, and dependency tree positions for each advisory. This prevents confirming whether each advisory affects a production dependency shipped in the browser bundle or a devDependency used only during build. The project's dependency profile (Babel, Jest, Webpack as devDependencies; browser-oriented libraries as production dependencies) and its browser-only runtime context strongly suggest most or all advisories affect build-time transitive dependencies with no runtime reachability in the shipped extension, but this cannot be definitively confirmed from the supplied evidence alone.

Impact: low · Exploitability: unlikely

Developer action: Run npm audit or osv-scanner locally with full output to identify each affected package, then update production dependencies first and devDependencies as convenient. Consider adding npm audit to CI to catch future advisories early.

Sources:

Scanner output omitted package names and locked versions for all dependency advisories

low risk · medium confidence

The scanner found security warnings for libraries used by this extension but did not include the specific library names. Based on how the extension works (running locally, with you controlling the inputs), the overall risk is low, but updating libraries when fixes are available is good practice.

Technical assessment

All seven OSV-Scanner candidates in this evidence set had their package details removed from the scanner output. The supplied source context shows only the root package dependency ranges, not the specific locked versions of the vulnerable packages or whether they are production or development dependencies. This limits the precision of runtime-reachability analysis. However, the project is a client-side browser extension where the user authors the primary inputs, and the README documents that dangerous capabilities require explicit opt-in. These factors collectively reduce the exploitability of dependency advisories regardless of which specific package is affected.

Impact: low · Exploitability: unlikely

Developer action: Run a dependency audit with package names visible to identify which specific packages and versions need updating, then upgrade them to patched releases.

Sources:

Coverage and limitations

Tools

Limitations

Technical scan identity