What this review found
No material or immediate-danger item was identified.
Minor cautions
Dependency advisory GHSA-4x5r-pxfx-6jf8 applies
Minor caution · low confidence
A dependency advisory was flagged, but the specific affected package cannot be identified from the provided evidence. This project is a browser-based SillyTavern extension that ships as a bundled file, so most dependency advisories in build-time tools do not reach end users.
Technical evidence
Scanner reason: OSV-Scanner matched advisory GHSA-4x5r-pxfx-6jf8 to a dependency declared by this repository.
Contextual assessment: The scanner flagged a low-severity advisory for a dependency in file, but package details were removed from the evidence. The project is a browser extension built with webpack; the shipped artifact is a bundle rather than the full node_modules tree. Many lockfile advisories affect dev-only or build-time transitive dependencies with no runtime reachability in the browser context. Without identifying the specific package and version, concrete user harm cannot be established.
Impact: none · Exploitability: unlikely
Developer action: none
- Scanner
- osv-scanner 2.4.0
- Rule
- GHSA-4x5r-pxfx-6jf8
- File role
- production
- Source
- package-lock.json
Dependency advisory GHSA-fv7c-fp4j-7gwp applies
Minor caution · low confidence
A high-severity advisory was flagged for a dependency, but the affected package cannot be identified from the evidence. Since this is a browser extension that ships a bundled file, the vulnerable code is likely in a build-time tool that does not run for end users.
Technical evidence
Scanner reason: OSV-Scanner matched advisory GHSA-fv7c-fp4j-7gwp to a dependency declared by this repository.
Contextual assessment: The scanner flagged a high-severity advisory but removed package details. The lockfile includes extensive dev dependencies (babel, jest, webpack, sass, ts-loader) whose transitive dependencies commonly carry advisories for server-side or filesystem operations irrelevant to a browser extension runtime. The production dependencies listed are at recent versions. Without the specific package identity, runtime reachability and concrete harm cannot be confirmed.
Impact: low · Exploitability: unlikely
Developer action: none
- Scanner
- osv-scanner 2.4.0
- Rule
- GHSA-fv7c-fp4j-7gwp
- File role
- production
- Source
- package-lock.json
Dependency advisory GHSA-mh29-5h37-fv8m applies
Minor caution · low confidence
A medium-severity dependency advisory was flagged, but the specific package is unknown. As a browser extension, the vulnerable code likely does not reach end users at runtime.
Technical evidence
Scanner reason: OSV-Scanner matched advisory GHSA-mh29-5h37-fv8m to a dependency declared by this repository.
Contextual assessment: The scanner flagged a medium-severity advisory with package details removed. The project ships as a webpack bundle for a browser-based SillyTavern extension. Without identifying the affected package, whether it is a production or dev dependency, and whether the vulnerable code path is reachable at runtime, no concrete user harm can be established.
Impact: none · Exploitability: unlikely
Developer action: none
- Scanner
- osv-scanner 2.4.0
- Rule
- GHSA-mh29-5h37-fv8m
- File role
- production
- Source
- package-lock.json
Dependency advisory GHSA-jp2q-39xq-3w4g applies
Minor caution · low confidence
A medium-severity dependency advisory was flagged, but the affected package cannot be identified. The browser extension context limits runtime exposure to most dependency vulnerabilities.
Technical evidence
Scanner reason: OSV-Scanner matched advisory GHSA-jp2q-39xq-3w4g to a dependency declared by this repository.
Contextual assessment: The scanner flagged a medium-severity advisory with package details removed. The lockfile contains both production and dev dependencies; many advisories in npm ecosystems affect build-time tooling. The shipped extension is a browser bundle. Without the specific package identity and version, runtime reachability cannot be determined.
Impact: none · Exploitability: unlikely
Developer action: none
- Scanner
- osv-scanner 2.4.0
- Rule
- GHSA-jp2q-39xq-3w4g
- File role
- production
- Source
- package-lock.json
Dependency advisory GHSA-7rx3-28cr-v5wh applies
Minor caution · low confidence
A medium-severity dependency advisory was flagged, but the specific package is unknown. The browser extension ships a bundle, limiting runtime exposure.
Technical evidence
Scanner reason: OSV-Scanner matched advisory GHSA-7rx3-28cr-v5wh to a dependency declared by this repository.
Contextual assessment: The scanner flagged a medium-severity advisory with package details removed. The project is a browser-based SillyTavern extension built with webpack. Without identifying the affected package, its dependency category, and runtime reachability, no concrete harm can be established.
Impact: none · Exploitability: unlikely
Developer action: none
- Scanner
- osv-scanner 2.4.0
- Rule
- GHSA-7rx3-28cr-v5wh
- File role
- production
- Source
- package-lock.json
Dependency advisory GHSA-qj8w-gfj5-8c6v applies
Minor caution · low confidence
A medium-severity dependency advisory was flagged, but the affected package cannot be identified. The browser extension context limits runtime exposure.
Technical evidence
Scanner reason: OSV-Scanner matched advisory GHSA-qj8w-gfj5-8c6v to a dependency declared by this repository.
Contextual assessment: The scanner flagged a medium-severity advisory with package details removed. The lockfile includes many dev-only dependencies whose transitive packages commonly carry advisories. The shipped artifact is a webpack bundle for a browser extension. Without the specific package identity, runtime reachability cannot be determined.
Impact: none · Exploitability: unlikely
Developer action: none
- Scanner
- osv-scanner 2.4.0
- Rule
- GHSA-qj8w-gfj5-8c6v
- File role
- production
- Source
- package-lock.json
Dependency advisory GHSA-jmr7-xgp7-cmfj applies
Minor caution · low confidence
A high-severity advisory was flagged for a dependency, but the affected package cannot be identified. Since this is a browser extension shipping a bundled file, the vulnerable code is likely in a build-time tool that does not run for end users.
Technical evidence
Scanner reason: OSV-Scanner matched advisory GHSA-jmr7-xgp7-cmfj to a dependency declared by this repository.
Contextual assessment: The scanner flagged a high-severity advisory but removed package details. The lockfile includes extensive dev dependencies (babel, jest, webpack, sass) whose transitive dependencies commonly carry advisories for server-side or filesystem operations. The production dependencies are at recent versions. Without the specific package identity, runtime reachability and concrete harm cannot be confirmed.
Impact: low · Exploitability: unlikely
Developer action: none
- Scanner
- osv-scanner 2.4.0
- Rule
- GHSA-jmr7-xgp7-cmfj
- File role
- production
- Source
- package-lock.json
Dependency advisory GHSA-8gc5-j5rx-235r applies
Minor caution · low confidence
A high-severity advisory was flagged for a dependency, but the affected package cannot be identified. The browser extension ships a bundle, so the vulnerable code likely does not reach end users at runtime.
Technical evidence
Scanner reason: OSV-Scanner matched advisory GHSA-8gc5-j5rx-235r to a dependency declared by this repository.
Contextual assessment: The scanner flagged a high-severity advisory but removed package details. The project is a browser-based SillyTavern extension built with webpack. The lockfile includes many dev-only build tools whose transitive dependencies commonly carry advisories. Without identifying the specific affected package, its category, and runtime reachability, concrete user harm cannot be established.
Impact: low · Exploitability: unlikely
Developer action: none
- Scanner
- osv-scanner 2.4.0
- Rule
- GHSA-8gc5-j5rx-235r
- File role
- production
- Source
- package-lock.json
Dependency advisory GHSA-5c6j-r48x-rmvq applies
Minor caution · low confidence
A security scanner found a known vulnerability in one of the libraries this extension uses. However, the scanner did not specify which library, and many of this project's libraries are only used during development, not when the extension actually runs. The risk to users appears low.
Technical evidence
Scanner reason: OSV-Scanner matched advisory GHSA-5c6j-r48x-rmvq to a dependency declared by this repository.
Contextual assessment: Detailed technical wording was omitted by the public report safety filter.
Impact: low · Exploitability: unlikely
Developer action: Review the OSV-scanner report to identify the specific package, then update it if a fixed version is available.
- Scanner
- osv-scanner 2.4.0
- Rule
- GHSA-5c6j-r48x-rmvq
- File role
- production
- Source
- package-lock.json
Dependency advisory GHSA-9cx6-37pm-9jff applies
Minor caution · low confidence
A security scanner flagged a vulnerable library, but did not specify which one. Since this is a browser extension and many libraries are build-time only, the practical risk is likely low.
Technical evidence
Scanner reason: OSV-Scanner matched advisory GHSA-9cx6-37pm-9jff to a dependency declared by this repository.
Contextual assessment: OSV-scanner matched advisory GHSA-9cx6-37pm-9jff against a dependency in this browser extension's lockfile. Package details were removed from the scanner output, preventing identification of the affected package and version. The lockfile contains a large number of dev-only build dependencies that do not ship to runtime. Without the package identity, runtime reachability cannot be assessed. The browser-extension deployment context limits concrete harm from most common npm advisory classes.
Impact: low · Exploitability: unlikely
Developer action: Identify the flagged package from the full OSV-scanner output and update it if a patched version exists.
- Scanner
- osv-scanner 2.4.0
- Rule
- GHSA-9cx6-37pm-9jff
- File role
- production
- Source
- package-lock.json
Dependency advisory GHSA-37qj-frw5-hhjh applies
Minor caution · low confidence
A scanner found a vulnerable dependency but did not name it. Because this project runs in a browser and many dependencies are only used during development, the actual risk is likely low.
Technical evidence
Scanner reason: OSV-Scanner matched advisory GHSA-37qj-frw5-hhjh to a dependency declared by this repository.
Contextual assessment: OSV-scanner matched advisory GHSA-37qj-frw5-hhjh against a dependency in this lockfile. The scanner removed package details, so the affected package, its version, and whether it is a production or dev dependency cannot be determined from the supplied evidence. The project runs as a browser extension, which constrains the attack surface for most dependency vulnerabilities. No attacker-controlled input path to the vulnerable code can be confirmed without the package identity.
Impact: low · Exploitability: unlikely
Developer action: Check the full scanner output for the package name and update it if a fix is available.
- Scanner
- osv-scanner 2.4.0
- Rule
- GHSA-37qj-frw5-hhjh
- File role
- production
- Source
- package-lock.json
Dependency advisory GHSA-v2hh-gcrm-f6hx applies
Minor caution · low confidence
A security scanner flagged a vulnerable library without specifying which one. Since this is a browser extension with many build-only dependencies, the real-world risk is likely low.
Technical evidence
Scanner reason: OSV-Scanner matched advisory GHSA-v2hh-gcrm-f6hx to a dependency declared by this repository.
Contextual assessment: OSV-scanner matched advisory GHSA-v2hh-gcrm-f6hx against a dependency in this lockfile. Package details were stripped from the scanner output, preventing verification of which package and version are affected. The lockfile includes many dev-only build tool dependencies that are not present at runtime. The browser-extension execution context limits the practical impact of most npm advisory types. Runtime reachability cannot be confirmed without the package identity.
Impact: low · Exploitability: unlikely
Developer action: Identify the affected package from the complete scanner report and upgrade if a patched version is available.
- Scanner
- osv-scanner 2.4.0
- Rule
- GHSA-v2hh-gcrm-f6hx
- File role
- production
- Source
- package-lock.json
Dependency advisory GHSA-m7jm-9gc2-mpf2 applies
Minor caution · low confidence
A scanner found a critically-rated vulnerability in a library used by this extension, but did not specify which library. Because this is a browser extension and many libraries are only used during development, the actual danger to users cannot be confirmed and is likely limited.
Technical evidence
Scanner reason: OSV-Scanner matched advisory GHSA-m7jm-9gc2-mpf2 to a dependency declared by this repository.
Contextual assessment: OSV-scanner matched advisory GHSA-m7jm-9gc2-mpf2 with critical severity against a dependency in this lockfile. The scanner removed package details, so the affected package, its version, and whether it is a production or dev dependency cannot be determined. Although the advisory severity is critical, the project is a browser extension, and many lockfile entries are dev-only build tools. Without the package identity, runtime reachability, attacker input paths, and concrete user harm cannot be verified. Advisory severity alone does not establish immediate danger.
Impact: low · Exploitability: unlikely
Developer action: Prioritize identifying the critically-flagged package from the full scanner output. If it is a production dependency, update it immediately; if it is a dev dependency, update when convenient.
- Scanner
- osv-scanner 2.4.0
- Rule
- GHSA-m7jm-9gc2-mpf2
- File role
- production
- Source
- package-lock.json
Dependency advisory GHSA-2g4f-4pwh-qvx6 applies
Minor caution · low confidence
A scanner found a medium-severity vulnerability in a library but did not name it. The practical risk for this browser extension is likely low.
Technical evidence
Scanner reason: OSV-Scanner matched advisory GHSA-2g4f-4pwh-qvx6 to a dependency declared by this repository.
Contextual assessment: OSV-scanner matched advisory GHSA-2g4f-4pwh-qvx6 with medium severity against a dependency in this lockfile. Package details were removed from the scanner output, preventing identification of the affected package and version. The project is a browser extension with many dev-only dependencies. Without the package identity, runtime reachability and attacker input paths cannot be assessed. Medium-severity advisories in browser-extension contexts typically present low concrete risk.
Impact: low · Exploitability: unlikely
Developer action: Identify the flagged package from the full scanner report and update it if a fix is available.
- Scanner
- osv-scanner 2.4.0
- Rule
- GHSA-2g4f-4pwh-qvx6
- File role
- production
- Source
- package-lock.json
Dependency advisory GHSA-v39h-62p7-jpjc applies
Minor caution · low confidence
A scanner flagged a high-severity vulnerability in a library without specifying which one. Since this is a browser extension with many build-only dependencies, the actual risk is likely low.
Technical evidence
Scanner reason: OSV-Scanner matched advisory GHSA-v39h-62p7-jpjc to a dependency declared by this repository.
Contextual assessment: Detailed technical wording was omitted by the public report safety filter.
Impact: low · Exploitability: unlikely
Developer action: Identify the affected package from the complete scanner output and update it if a patched version exists.
- Scanner
- osv-scanner 2.4.0
- Rule
- GHSA-v39h-62p7-jpjc
- File role
- production
- Source
- package-lock.json
Dependency advisory GHSA-h67p-54hq-rp68 applies
Minor caution · low confidence
A scanner found a medium-severity vulnerability in a library but did not name it. The practical risk for this browser extension is likely low.
Technical evidence
Scanner reason: OSV-Scanner matched advisory GHSA-h67p-54hq-rp68 to a dependency declared by this repository.
Contextual assessment: OSV-scanner matched advisory GHSA-h67p-54hq-rp68 with medium severity against a dependency in this lockfile. Package details were removed from the scanner output, preventing identification of the affected package and version. The project is a browser extension with many dev-only dependencies. Without the package identity, runtime reachability and attacker input paths cannot be assessed. Medium-severity advisories in browser-extension contexts typically present low concrete risk.
Impact: low · Exploitability: unlikely
Developer action: Identify the flagged package from the full scanner report and update it if a fix is available.
- Scanner
- osv-scanner 2.4.0
- Rule
- GHSA-h67p-54hq-rp68
- File role
- production
- Source
- package-lock.json
Dependency advisory GHSA-q3j6-qgpj-74h6 applies
Minor caution · medium confidence
A flagged library was found in the project's dependency list. This extension runs inside a browser, and the flagged library is most likely a build tool that does not get included in the final product users install. The risk to end users is low.
Technical evidence
Scanner reason: OSV-Scanner matched advisory GHSA-q3j6-qgpj-74h6 to a dependency declared by this repository.
Contextual assessment: This advisory matches a dependency declared in the lockfile of a browser-based SillyTavern extension. The project builds with Babel, Jest, and Webpack (devDependencies), and many high-severity advisories in such lockfiles map to build-tool transitive dependencies that are not shipped to end users. The extension's runtime context is the SillyTavern browser sandbox, which limits the impact of server-side vulnerability classes such as path traversal or command injection. Without the specific package name and version (removed by the scanner), exact runtime reachability cannot be confirmed, but the project's stated purpose and dependency profile indicate this is most likely a build-time or transitive dependency issue with no direct attacker-controlled input path in the shipped extension.
Impact: low · Exploitability: unlikely
Developer action: Run npm audit to identify the specific package and update it if a patched version is available, prioritizing production dependencies over build tools.
- Scanner
- osv-scanner 2.4.0
- Rule
- GHSA-q3j6-qgpj-74h6
- File role
- production
- Source
- package-lock.json
Dependency advisory GHSA-wf6x-7x77-mvgw applies
Minor caution · medium confidence
A security scanner flagged a library used by this browser extension. Because the extension runs in a browser and the flagged library is likely a development tool not included in the final install, the practical risk is low.
Technical evidence
Scanner reason: OSV-Scanner matched advisory GHSA-wf6x-7x77-mvgw to a dependency declared by this repository.
Contextual assessment: This high-severity advisory was matched against the lockfile of a frontend SillyTavern extension. The project's production dependencies are browser-oriented libraries (CodeMirror, xyflow, handlebars, zod, zustand, html-to-image, fast-xml-parser). High-severity advisories in projects of this shape frequently correspond to transitive dependencies of devDependencies such as Babel or Jest, which are not present in the shipped bundle. The browser runtime context also means vulnerability classes targeting Node.js server environments are not reachable. The scanner removed package details, preventing confirmation of the exact affected package and version.
Impact: low · Exploitability: unlikely
Developer action: Run npm audit to identify the specific package and update it if a patched version is available.
- Scanner
- osv-scanner 2.4.0
- Rule
- GHSA-wf6x-7x77-mvgw
- File role
- production
- Source
- package-lock.json
Dependency advisory GHSA-gh4j-gqv2-49f6 applies
Minor caution · medium confidence
A scanner found a medium-risk issue in a library used by this project. Since the extension runs in a browser, the practical danger is likely minimal.
Technical evidence
Scanner reason: OSV-Scanner matched advisory GHSA-gh4j-gqv2-49f6 to a dependency declared by this repository.
Contextual assessment: This medium-severity advisory was matched against the lockfile. The project is a browser-based SillyTavern extension whose shipped artifact is a webpack bundle running in the SillyTavern frontend. Medium-severity advisories in such projects commonly affect build-time transitive dependencies or involve vulnerability classes (e.g., ReDoS, prototype pollution in server contexts) that have limited practical impact in a browser extension runtime. Package details were removed by the scanner, so the exact affected package and its position in the dependency tree cannot be confirmed.
Impact: low · Exploitability: unlikely
Developer action: Run npm audit to identify the specific package and update it if convenient.
- Scanner
- osv-scanner 2.4.0
- Rule
- GHSA-gh4j-gqv2-49f6
- File role
- production
- Source
- package-lock.json
Dependency advisory GHSA-23c5-xmqv-rm74 applies
Minor caution · medium confidence
A scanner flagged a library in this project's dependency list. The extension runs in a browser, and the flagged library is probably a development tool not shipped to users, so the risk is low.
Technical evidence
Scanner reason: OSV-Scanner matched advisory GHSA-23c5-xmqv-rm74 to a dependency declared by this repository.
Contextual assessment: This high-severity advisory was matched against the lockfile of a browser-based SillyTavern extension. The project uses Babel, Jest, and Webpack as devDependencies, and high-severity advisories in such lockfiles frequently map to transitive dependencies of these build tools. The shipped extension is a browser bundle, so Node.js server-side vulnerability classes are not reachable at runtime. The scanner removed package details, preventing exact identification of the affected package and confirmation of whether it is a production or development dependency.
Impact: low · Exploitability: unlikely
Developer action: Run npm audit to identify the specific package and update it if a patched version is available.
- Scanner
- osv-scanner 2.4.0
- Rule
- GHSA-23c5-xmqv-rm74
- File role
- production
- Source
- package-lock.json
Dependency advisory GHSA-3jxr-9vmj-r5cp applies
Minor caution · medium confidence
A scanner found a high-risk flag on a library in this project. Because the extension runs in a browser and the library is likely a build-time tool, the actual risk to users is low.
Technical evidence
Scanner reason: OSV-Scanner matched advisory GHSA-3jxr-9vmj-r5cp to a dependency declared by this repository.
Contextual assessment: This high-severity advisory was matched against the lockfile. The project is a frontend SillyTavern extension that ships a webpack bundle to the browser. High-severity advisories in projects with this dependency profile (Babel, Jest, Webpack devDependencies) commonly correspond to build-tool transitive dependencies not present in the shipped artifact. The browser runtime context limits the impact of server-side vulnerability classes. Package details were removed by the scanner, so the exact affected package and its dependency tree position cannot be confirmed.
Impact: low · Exploitability: unlikely
Developer action: Run npm audit to identify the specific package and update it if a patched version is available.
- Scanner
- osv-scanner 2.4.0
- Rule
- GHSA-3jxr-9vmj-r5cp
- File role
- production
- Source
- package-lock.json
Dependency advisory GHSA-2w6w-674q-4c4q applies
Minor caution · medium confidence
A scanner flagged a critical issue in a library used by this project. However, this extension runs in a browser, and critical library issues in such projects usually affect build tools that are not included in what users actually install. The practical risk is low, but the developer should verify which package is affected.
Technical evidence
Scanner reason: OSV-Scanner matched advisory GHSA-2w6w-674q-4c4q to a dependency declared by this repository.
Contextual assessment: This critical-severity advisory was matched against the lockfile of a browser-based SillyTavern extension. Critical advisories in Node.js project lockfiles frequently involve packages such as tar, cross-spawn, or similar transitive dependencies of build tooling (node-gyp, npm lifecycle scripts) that are devDependencies and are not included in the shipped browser bundle. The extension's runtime is the SillyTavern browser frontend, where server-side vulnerability classes are not applicable. The scanner removed package details, so the exact affected package cannot be confirmed; however, the project's dependency profile and browser-only runtime strongly suggest this is a build-time dependency issue with no runtime reachability in the shipped extension.
Impact: low · Exploitability: unlikely
Developer action: Run npm audit to identify the specific package. If it is a production dependency, update it immediately. If it is a devDependency, update it when convenient to keep the build environment clean.
- Scanner
- osv-scanner 2.4.0
- Rule
- GHSA-2w6w-674q-4c4q
- File role
- production
- Source
- package-lock.json
Dependency advisory GHSA-xjpj-3mr7-gcpf applies
Minor caution · medium confidence
A scanner flagged a library in this project. Since the extension runs in a browser and the library is likely a development tool, the risk to users is low.
Technical evidence
Scanner reason: OSV-Scanner matched advisory GHSA-xjpj-3mr7-gcpf to a dependency declared by this repository.
Contextual assessment: This high-severity advisory was matched against the lockfile of a browser-based SillyTavern extension. The project's production dependencies are browser-oriented libraries, and its devDependencies include Babel, Jest, and Webpack. High-severity advisories in such lockfiles commonly map to transitive dependencies of build tools that are not shipped to end users. The browser runtime context limits the impact of server-side vulnerability classes. Package details were removed by the scanner, preventing exact identification.
Impact: low · Exploitability: unlikely
Developer action: Run npm audit to identify the specific package and update it if a patched version is available.
- Scanner
- osv-scanner 2.4.0
- Rule
- GHSA-xjpj-3mr7-gcpf
- File role
- production
- Source
- package-lock.json
Dependency advisory GHSA-v56q-mh7h-f735 applies
Minor caution · medium confidence
A scanner found a high-risk flag on a library in this project. Because the extension runs in a browser and the library is likely a build-time tool, the actual risk to users is low.
Technical evidence
Scanner reason: OSV-Scanner matched advisory GHSA-v56q-mh7h-f735 to a dependency declared by this repository.
Contextual assessment: This high-severity advisory was matched against the lockfile of a browser-based SillyTavern extension. The project ships a webpack bundle to the SillyTavern browser frontend. High-severity advisories in projects with this dependency profile frequently correspond to build-tool transitive dependencies not present in the shipped artifact. The browser runtime context means server-side vulnerability classes are not reachable. Package details were removed by the scanner, so the exact affected package and its position in the dependency tree cannot be confirmed.
Impact: low · Exploitability: unlikely
Developer action: Run npm audit to identify the specific package and update it if a patched version is available.
- Scanner
- osv-scanner 2.4.0
- Rule
- GHSA-v56q-mh7h-f735
- File role
- production
- Source
- package-lock.json
Dependency advisory GHSA-7p8r-x3mc-p8w7 applies
Minor caution · medium confidence
A security tool found that this project uses a software library with a known issue. Because this is a browser extension for a local roleplay tool, this issue is unlikely to cause serious harm and is something the developer should update when convenient.
Technical evidence
Scanner reason: OSV-Scanner matched advisory GHSA-7p8r-x3mc-p8w7 to a dependency declared by this repository.
Contextual assessment: The scanner matched a known advisory for a declared dependency. This project is a front-end SillyTavern extension. Vulnerabilities in this context typically affect either build-time devDependencies (which are not shipped to users) or front-end libraries where the user controls the environment and inputs. Typical impacts are XSS or ReDoS, which have limited severity in a local user-controlled roleplay tool. Without specific package details and runtime reachability analysis, this is treated as a minor weakness.
Impact: low · Exploitability: unlikely
Developer action: Update the flagged dependency to a patched version. Verify if the vulnerable code is actually reachable in the extension's runtime.
- Scanner
- osv-scanner 2.4.0
- Rule
- GHSA-7p8r-x3mc-p8w7
- File role
- production
- Source
- package-lock.json
Dependency advisory GHSA-7r86-cg39-jmmj applies
Minor caution · medium confidence
A security tool found that this project uses a software library with a known issue. Because this is a browser extension for a local roleplay tool, this issue is unlikely to cause serious harm and is something the developer should update when convenient.
Technical evidence
Scanner reason: OSV-Scanner matched advisory GHSA-7r86-cg39-jmmj to a dependency declared by this repository.
Contextual assessment: The scanner matched a known advisory for a declared dependency. This project is a front-end SillyTavern extension. Vulnerabilities in this context typically affect either build-time devDependencies (which are not shipped to users) or front-end libraries where the user controls the environment and inputs. Typical impacts are XSS or ReDoS, which have limited severity in a local user-controlled roleplay tool. Without specific package details and runtime reachability analysis, this is treated as a minor weakness.
Impact: low · Exploitability: unlikely
Developer action: Update the flagged dependency to a patched version. Verify if the vulnerable code is actually reachable in the extension's runtime.
- Scanner
- osv-scanner 2.4.0
- Rule
- GHSA-7r86-cg39-jmmj
- File role
- production
- Source
- package-lock.json
Dependency advisory GHSA-6g55-p6wh-862q applies
Minor caution · medium confidence
A security tool found that this project uses a software library with a known issue. Because this is a browser extension for a local roleplay tool, this issue is unlikely to cause serious harm and is something the developer should update when convenient.
Technical evidence
Scanner reason: OSV-Scanner matched advisory GHSA-6g55-p6wh-862q to a dependency declared by this repository.
Contextual assessment: The scanner matched a known advisory for a declared dependency. This project is a front-end SillyTavern extension. Vulnerabilities in this context typically affect either build-time devDependencies (which are not shipped to users) or front-end libraries where the user controls the environment and inputs. Typical impacts are XSS or ReDoS, which have limited severity in a local user-controlled roleplay tool. Without specific package details and runtime reachability analysis, this is treated as a minor weakness.
Impact: low · Exploitability: unlikely
Developer action: Update the flagged dependency to a patched version. Verify if the vulnerable code is actually reachable in the extension's runtime.
- Scanner
- osv-scanner 2.4.0
- Rule
- GHSA-6g55-p6wh-862q
- File role
- production
- Source
- package-lock.json
Dependency advisory GHSA-8fgc-7cc6-rx7x applies
Minor caution · medium confidence
A security tool found that this project uses a software library with a known issue. Because this is a browser extension for a local roleplay tool, this issue is unlikely to cause serious harm and is something the developer should update when convenient.
Technical evidence
Scanner reason: OSV-Scanner matched advisory GHSA-8fgc-7cc6-rx7x to a dependency declared by this repository.
Contextual assessment: The scanner matched a known advisory for a declared dependency. This project is a front-end SillyTavern extension. Vulnerabilities in this context typically affect either build-time devDependencies (which are not shipped to users) or front-end libraries where the user controls the environment and inputs. Typical impacts are XSS or ReDoS, which have limited severity in a local user-controlled roleplay tool. Without specific package details and runtime reachability analysis, this is treated as a minor weakness.
Impact: low · Exploitability: unlikely
Developer action: Update the flagged dependency to a patched version. Verify if the vulnerable code is actually reachable in the extension's runtime.
- Scanner
- osv-scanner 2.4.0
- Rule
- GHSA-8fgc-7cc6-rx7x
- File role
- production
- Source
- package-lock.json
Dependency advisory GHSA-r28c-9q8g-f849 applies
Minor caution · medium confidence
A security tool found that this project uses a software library with a known issue. Because this is a browser extension for a local roleplay tool, this issue is unlikely to cause serious harm and is something the developer should update when convenient.
Technical evidence
Scanner reason: OSV-Scanner matched advisory GHSA-r28c-9q8g-f849 to a dependency declared by this repository.
Contextual assessment: The scanner matched a known advisory for a declared dependency. This project is a front-end SillyTavern extension. Vulnerabilities in this context typically affect either build-time devDependencies (which are not shipped to users) or front-end libraries where the user controls the environment and inputs. Typical impacts are XSS or ReDoS, which have limited severity in a local user-controlled roleplay tool. Without specific package details and runtime reachability analysis, this is treated as a minor weakness.
Impact: low · Exploitability: unlikely
Developer action: Update the flagged dependency to a patched version. Verify if the vulnerable code is actually reachable in the extension's runtime.
- Scanner
- osv-scanner 2.4.0
- Rule
- GHSA-r28c-9q8g-f849
- File role
- production
- Source
- package-lock.json
Dependency advisory GHSA-xhpv-hc6g-r9c6 applies
Minor caution · medium confidence
A security tool found that this project uses a software library with a known issue. Because this is a browser extension for a local roleplay tool, this issue is unlikely to cause serious harm and is something the developer should update when convenient.
Technical evidence
Scanner reason: OSV-Scanner matched advisory GHSA-xhpv-hc6g-r9c6 to a dependency declared by this repository.
Contextual assessment: The scanner matched a known advisory for a declared dependency. This project is a front-end SillyTavern extension. Vulnerabilities in this context typically affect either build-time devDependencies (which are not shipped to users) or front-end libraries where the user controls the environment and inputs. Typical impacts are XSS or ReDoS, which have limited severity in a local user-controlled roleplay tool. Without specific package details and runtime reachability analysis, this is treated as a minor weakness.
Impact: low · Exploitability: unlikely
Developer action: Update the flagged dependency to a patched version. Verify if the vulnerable code is actually reachable in the extension's runtime.
- Scanner
- osv-scanner 2.4.0
- Rule
- GHSA-xhpv-hc6g-r9c6
- File role
- production
- Source
- package-lock.json
Dependency advisory GHSA-xvcm-6775-5m9r applies
Minor caution · medium confidence
A security tool found that this project uses a software library with a known issue. Because this is a browser extension for a local roleplay tool, this issue is unlikely to cause serious harm and is something the developer should update when convenient.
Technical evidence
Scanner reason: OSV-Scanner matched advisory GHSA-xvcm-6775-5m9r to a dependency declared by this repository.
Contextual assessment: The scanner matched a known advisory for a declared dependency. This project is a front-end SillyTavern extension. Vulnerabilities in this context typically affect either build-time devDependencies (which are not shipped to users) or front-end libraries where the user controls the environment and inputs. Typical impacts are XSS or ReDoS, which have limited severity in a local user-controlled roleplay tool. Without specific package details and runtime reachability analysis, this is treated as a minor weakness.
Impact: low · Exploitability: unlikely
Developer action: Update the flagged dependency to a patched version. Verify if the vulnerable code is actually reachable in the extension's runtime.
- Scanner
- osv-scanner 2.4.0
- Rule
- GHSA-xvcm-6775-5m9r
- File role
- production
- Source
- package-lock.json
Dependency advisory GHSA-3v7f-55p6-f55p applies
Minor caution · medium confidence
A security tool found that this project uses a software library with a known issue. Because this is a browser extension for a local roleplay tool, this issue is unlikely to cause serious harm and is something the developer should update when convenient.
Technical evidence
Scanner reason: OSV-Scanner matched advisory GHSA-3v7f-55p6-f55p to a dependency declared by this repository.
Contextual assessment: The scanner matched a known advisory for a declared dependency. This project is a front-end SillyTavern extension. Vulnerabilities in this context typically affect either build-time devDependencies (which are not shipped to users) or front-end libraries where the user controls the environment and inputs. Typical impacts are XSS or ReDoS, which have limited severity in a local user-controlled roleplay tool. Without specific package details and runtime reachability analysis, this is treated as a minor weakness.
Impact: low · Exploitability: unlikely
Developer action: Update the flagged dependency to a patched version. Verify if the vulnerable code is actually reachable in the extension's runtime.
- Scanner
- osv-scanner 2.4.0
- Rule
- GHSA-3v7f-55p6-f55p
- File role
- production
- Source
- package-lock.json
Dependency advisory GHSA-3mfm-83xf-c92r applies
Minor caution · low confidence
A scanner flagged a dependency as having a known security issue, but the evidence does not show which package or whether it is actually used when the extension runs. Many flagged packages in this project are likely build tools that never reach the user's browser.
Technical evidence
Scanner reason: OSV-Scanner matched advisory GHSA-3mfm-83xf-c92r to a dependency declared by this repository.
Contextual assessment: OSV-scanner matched a high-severity advisory against a dependency in the lockfile. The provided source context only shows the top-level dependency declarations and the first portion of the lockfile; the specific vulnerable package name, resolved version, and whether it is a production or dev dependency are not visible in the supplied evidence. This project is a browser-based SillyTavern extension built with webpack and babel, so many transitive dependencies are build-time only and are not shipped in the runtime bundle. Without confirmed package identity, version applicability, and runtime reachability, the advisory cannot be elevated beyond a minor weakness.
Impact: low · Exploitability: unlikely
Developer action: Review the OSV-scanner output to identify the specific package, confirm whether it is a dev dependency, and update it if a patched version is available.
- Scanner
- osv-scanner 2.4.0
- Rule
- GHSA-3mfm-83xf-c92r
- File role
- production
- Source
- package-lock.json
Dependency advisory GHSA-4c8g-83qw-93j6 applies
Minor caution · low confidence
A scanner flagged a dependency, but the evidence does not confirm which package it is or whether it affects the running extension. If it is a build-only tool, it poses no direct risk to users.
Technical evidence
Scanner reason: OSV-Scanner matched advisory GHSA-4c8g-83qw-93j6 to a dependency declared by this repository.
Contextual assessment: OSV-scanner matched a high-severity advisory against a lockfile dependency. The supplied evidence does not include the flagged package name, resolved version, or dependency tier. The project bundles a browser extension via webpack; transitive build-tool dependencies are not part of the shipped runtime. Without confirming the package identity and runtime reachability, this remains a minor weakness.
Impact: low · Exploitability: unlikely
Developer action: Identify the specific package from the scanner output, verify whether it ships at runtime, and update to a patched version if available.
- Scanner
- osv-scanner 2.4.0
- Rule
- GHSA-4c8g-83qw-93j6
- File role
- production
- Source
- package-lock.json
Dependency advisory GHSA-w5hq-g745-h8pq applies
Minor caution · low confidence
A scanner flagged a dependency with a medium-severity issue, but the evidence does not show which package or whether it is used at runtime. The risk to end users is likely low.
Technical evidence
Scanner reason: OSV-Scanner matched advisory GHSA-w5hq-g745-h8pq to a dependency declared by this repository.
Contextual assessment: OSV-scanner matched a medium-severity advisory against a lockfile dependency. The evidence does not identify the specific package, resolved version, or whether it is a production or dev dependency. Runtime reachability and attacker input control cannot be confirmed from the supplied source context. The project is a browser extension where many transitive dependencies are build-time only.
Impact: low · Exploitability: unlikely
Developer action: Identify the flagged package, confirm runtime usage, and update if a patched version exists.
- Scanner
- osv-scanner 2.4.0
- Rule
- GHSA-w5hq-g745-h8pq
- File role
- production
- Source
- package-lock.json
Dependency advisory GHSA-f886-m6hf-6m8v applies
Minor caution · low confidence
A scanner flagged a dependency, but the evidence does not confirm which package or whether it runs in the extension. The user-facing risk is likely low.
Technical evidence
Scanner reason: OSV-Scanner matched advisory GHSA-f886-m6hf-6m8v to a dependency declared by this repository.
Contextual assessment: OSV-scanner matched a medium-severity advisory against a lockfile dependency. The specific package name, resolved version, and dependency tier are not present in the supplied evidence. Without confirming runtime reachability and attacker-controlled input paths, this cannot be elevated beyond a minor weakness.
Impact: low · Exploitability: unlikely
Developer action: Identify the flagged package from scanner output, verify whether it ships at runtime, and update if a fix is available.
- Scanner
- osv-scanner 2.4.0
- Rule
- GHSA-f886-m6hf-6m8v
- File role
- production
- Source
- package-lock.json
Dependency advisory GHSA-fj3w-jwp8-x2g3 applies
Minor caution · low confidence
A low-severity issue was flagged in a dependency the extension uses. The version is recent and the impact is likely minimal, but updating is still good practice.
Technical evidence
Scanner reason: OSV-Scanner matched advisory GHSA-fj3w-jwp8-x2g3 to a dependency declared by this repository.
Contextual assessment: OSV-scanner matched a low-severity advisory, likely against fast-xml-parser which is declared as a production dependency at version ^5.2.5. The advisory severity is low and the declared version is recent. The supplied evidence does not show the exact resolved version or confirm that the vulnerable code path is reachable with attacker-controlled XML input at runtime. Given the low severity and uncertainty, this is a minor weakness.
Impact: low · Exploitability: unlikely
Developer action: Confirm the resolved fast-xml-parser version is at or above the patched version and update if necessary.
- Scanner
- osv-scanner 2.4.0
- Rule
- GHSA-fj3w-jwp8-x2g3
- File role
- production
- Source
- package-lock.json
Dependency advisory GHSA-qx2v-qp2m-jg93 applies
Minor caution · low confidence
A scanner flagged a dependency with a medium issue, but the evidence does not show which package or whether it runs in the extension. The risk to users is likely low.
Technical evidence
Scanner reason: OSV-Scanner matched advisory GHSA-qx2v-qp2m-jg93 to a dependency declared by this repository.
Contextual assessment: OSV-scanner matched a medium-severity advisory against a lockfile dependency. The evidence does not identify the specific package, resolved version, or dependency tier. Runtime reachability and attacker input control cannot be confirmed. The project is a browser extension where many transitive dependencies are build-time only.
Impact: low · Exploitability: unlikely
Developer action: Identify the flagged package, confirm runtime usage, and update if a patched version exists.
- Scanner
- osv-scanner 2.4.0
- Rule
- GHSA-qx2v-qp2m-jg93
- File role
- production
- Source
- package-lock.json
Dependency advisory GHSA-52cp-r559-cp3m applies
Minor caution · low confidence
A scanner flagged a dependency with a high-severity label, but the evidence does not confirm which package or whether it is used when the extension runs. If it is a build-only tool, it poses no direct risk to users.
Technical evidence
Scanner reason: OSV-Scanner matched advisory GHSA-52cp-r559-cp3m to a dependency declared by this repository.
Contextual assessment: OSV-scanner matched a high-severity advisory against a lockfile dependency. The supplied evidence does not include the flagged package name, resolved version, or dependency tier. The project bundles a browser extension via webpack; transitive build-tool dependencies are not part of the shipped runtime. Without confirming package identity and runtime reachability, this remains a minor weakness.
Impact: low · Exploitability: unlikely
Developer action: Identify the specific package from scanner output, verify whether it ships at runtime, and update to a patched version if available.
- Scanner
- osv-scanner 2.4.0
- Rule
- GHSA-52cp-r559-cp3m
- File role
- production
- Source
- package-lock.json
Dependency advisory GHSA-fxqj-rqcc-2cmp applies
Minor caution · low confidence
A scanner flagged a dependency, but the evidence does not confirm which package or whether it runs in the extension. The user-facing risk is likely low.
Technical evidence
Scanner reason: OSV-Scanner matched advisory GHSA-fxqj-rqcc-2cmp to a dependency declared by this repository.
Contextual assessment: OSV-scanner matched a medium-severity advisory against a lockfile dependency. The specific package name, resolved version, and dependency tier are not present in the supplied evidence. Without confirming runtime reachability and attacker-controlled input paths, this cannot be elevated beyond a minor weakness.
Impact: low · Exploitability: unlikely
Developer action: Identify the flagged package from scanner output, verify whether it ships at runtime, and update if a fix is available.
- Scanner
- osv-scanner 2.4.0
- Rule
- GHSA-fxqj-rqcc-2cmp
- File role
- production
- Source
- package-lock.json
Dependency advisory GHSA-3ppc-4f35-3m26 applies
Minor caution · medium confidence
A security warning was found for a library used by this extension. Because the extension runs on your own computer and you create the content it processes, it is unlikely an attacker could trigger the problem.
Technical evidence
Scanner reason: OSV-Scanner matched advisory GHSA-3ppc-4f35-3m26 to a dependency declared by this repository.
Contextual assessment: A high-severity advisory was matched against a dependency in this client-side SillyTavern extension. The extension runs locally in the user's browser, and its primary inputs are flowcharts the user authors themselves. Without attacker-controlled input reaching the vulnerable code path at runtime, the advisory represents a latent weakness rather than an exploitable vulnerability in this deployment context. The specific package and locked version were not included in the supplied evidence, preventing precise runtime-reachability analysis.
Impact: low · Exploitability: unlikely
Developer action: Update the affected dependency to a patched version when a compatible release is available.
- Scanner
- osv-scanner 2.4.0
- Rule
- GHSA-3ppc-4f35-3m26
- File role
- production
- Source
- package-lock.json
Dependency advisory GHSA-mh99-v99m-4gvg applies
Minor caution · medium confidence
A security warning was found for a library used by this extension. Since you control what the extension processes and it runs locally, the risk of someone exploiting this is low.
Technical evidence
Scanner reason: OSV-Scanner matched advisory GHSA-mh99-v99m-4gvg to a dependency declared by this repository.
Contextual assessment: A high-severity advisory was matched against a dependency in this browser-based extension. The project processes user-authored flowchart definitions and chat content within the local SillyTavern environment. The advisory's severity reflects worst-case scenarios that typically require attacker-controlled input to reach the vulnerable function. In this context, inputs are primarily user-controlled, limiting runtime reachability. Package details were stripped from the scanner output, so exact version confirmation is not possible from the supplied evidence.
Impact: low · Exploitability: unlikely
Developer action: Update the affected dependency to a patched version when a compatible release is available.
- Scanner
- osv-scanner 2.4.0
- Rule
- GHSA-mh99-v99m-4gvg
- File role
- production
- Source
- package-lock.json
Dependency advisory GHSA-c2c7-rcm5-vvqj applies
Minor caution · medium confidence
A security warning was found for a library used by this extension. Because the extension runs on your computer and you control its inputs, it is unlikely an attacker could exploit this.
Technical evidence
Scanner reason: OSV-Scanner matched advisory GHSA-c2c7-rcm5-vvqj to a dependency declared by this repository.
Contextual assessment: A high-severity advisory was matched against a dependency in this local browser extension. The extension's data flows are primarily user-driven: the user creates flowcharts, connects nodes, and triggers execution manually or through SillyTavern events. The advisory severity reflects potential impact under attacker-controlled input conditions that are not present in normal use. The scanner removed package details, so the exact vulnerable version and its runtime reachability cannot be confirmed from the supplied evidence alone.
Impact: low · Exploitability: unlikely
Developer action: Update the affected dependency to a patched version when a compatible release is available.
- Scanner
- osv-scanner 2.4.0
- Rule
- GHSA-c2c7-rcm5-vvqj
- File role
- production
- Source
- package-lock.json
Dependency advisory GHSA-2qvq-rjwj-gvw9 applies
Minor caution · medium confidence
A moderate security warning was found for a library used by this extension. Since you control what the extension processes, the risk is low.
Technical evidence
Scanner reason: OSV-Scanner matched advisory GHSA-2qvq-rjwj-gvw9 to a dependency declared by this repository.
Contextual assessment: A medium-severity advisory was matched against a dependency in this client-side extension. The project operates within the SillyTavern browser environment, processing user-authored flowchart configurations. Medium-severity advisories typically require specific attacker-controlled input to reach the vulnerable code path. In this context, the user is the primary input source, reducing exploitability. Package details were not included in the scanner output.
Impact: low · Exploitability: unlikely
Developer action: Update the affected dependency to a patched version when a compatible release is available.
- Scanner
- osv-scanner 2.4.0
- Rule
- GHSA-2qvq-rjwj-gvw9
- File role
- production
- Source
- package-lock.json
Dependency advisory GHSA-rgw5-rvv9-x895 applies
Minor caution · medium confidence
A security warning was found for a library used by this extension. Because the extension runs locally and you control its inputs, the risk of exploitation is low.
Technical evidence
Scanner reason: OSV-Scanner matched advisory GHSA-rgw5-rvv9-x895 to a dependency declared by this repository.
Contextual assessment: A high-severity advisory was matched against a dependency in this local browser extension. The extension processes user-authored flowchart data and SillyTavern chat content. While the advisory severity is high, exploitation typically requires attacker-controlled input to reach the vulnerable function. The extension's design requires users to explicitly enable dangerous nodes, and primary data flows are user-controlled. The scanner stripped package details, preventing exact version and reachability confirmation.
Impact: low · Exploitability: unlikely
Developer action: Update the affected dependency to a patched version when a compatible release is available.
- Scanner
- osv-scanner 2.4.0
- Rule
- GHSA-rgw5-rvv9-x895
- File role
- production
- Source
- package-lock.json
Expected scanner matches (4)
Dependency advisory GHSA-442j-39wm-28r2 applies
Expected behavior · medium confidence
A minor security note was found for a library used by this extension. The issue is low severity and unlikely to cause any real problem in this extension.
Technical evidence
Scanner reason: OSV-Scanner matched advisory GHSA-442j-39wm-28r2 to a dependency declared by this repository.
Contextual assessment: A low-severity advisory was matched against a dependency in this extension. Low-severity advisories often affect development-only toolchains or describe theoretical issues with minimal concrete impact. The extension is a client-side browser application with user-authored inputs. Without evidence that attacker-controlled data reaches the vulnerable code at runtime, and given the low severity rating, this does not represent a material risk in this context.
Impact: none · Exploitability: unlikely
Developer action: none
- Scanner
- osv-scanner 2.4.0
- Rule
- GHSA-442j-39wm-28r2
- File role
- production
- Source
- package-lock.json
OpenGrep reported tavernkeeper.dynamic-execution.javascript-eval
Expected behavior · high confidence
This is a visual programming block that lets the user write and run their own JavaScript as part of a flow. Running custom code is exactly what the block is for, and the project warns users it is dangerous and requires them to turn on a special toggle before it will run. This is an intended feature, not a hidden threat.
Technical evidence
Scanner reason: OpenGrep matched static-analysis rule tavernkeeper.dynamic-execution.javascript-eval in this repository.
Contextual assessment: The flagged line constructs a function from user-supplied node data and executes it with input, variables, and the SillyTavern context. This is the explicit, stated purpose of the Execute JS Code node in a visual flow editor. The node definition marks itself as dangerous and the project documentation states such nodes only run when the user explicitly enables an Allow Dangerous toggle for a specific flow. The executed code originates from the flow author, not from an external attacker-controlled source, and execution is gated behind a documented user opt-in. No concealed exfiltration, hidden persistence, or obfuscation is present.
Impact: high · Exploitability: plausible
Developer action: none
- Scanner
- opengrep 1.26.0
- Rule
- tavernkeeper.dynamic-execution.javascript-eval
- File role
- production
- Source
- src/components/nodes/ExecuteJsNode/definition.ts:27
Dependency advisory GHSA-38r7-794h-5758 applies
Expected behavior · medium confidence
A minor security note was found for a library used by this extension. The issue is low severity and unlikely to affect you.
Technical evidence
Scanner reason: OSV-Scanner matched advisory GHSA-38r7-794h-5758 to a dependency declared by this repository.
Contextual assessment: A low-severity advisory was matched against a dependency in this extension. The project is a browser-based SillyTavern extension with user-controlled inputs. Low-severity advisories frequently describe issues with minimal real-world impact or affect development-only dependencies that do not ship to runtime. Without evidence of attacker-controlled input reaching the vulnerable code, this does not represent a material risk.
Impact: none · Exploitability: unlikely
Developer action: none
- Scanner
- osv-scanner 2.4.0
- Rule
- GHSA-38r7-794h-5758
- File role
- production
- Source
- package-lock.json
OpenGrep reported tavernkeeper.dynamic-execution.javascript-eval
Expected behavior · high confidence
This extension lets users build visual flowcharts that can run custom JavaScript inside an If node. The project clearly warns that this is a dangerous feature and requires the user to turn on an Allow Dangerous switch before it will run. Since the user writes the code themselves and must explicitly enable it, this is intended behavior, not a security problem.
Technical evidence
Scanner reason: OpenGrep matched static-analysis rule tavernkeeper.dynamic-execution.javascript-eval in this repository.
Contextual assessment: The matched construct dynamically constructs a function from condition.code, which is user-authored logic entered into an If node's advanced code editor. This is a core, disclosed feature of a visual flowchart automation extension. The project documentation explicitly labels the If node as dangerous in advanced mode and states such nodes only execute when the user enables the per-flow Allow Dangerous toggle. The code runs locally in the user's own browser extension context, is authored by the user themselves, and is gated behind an explicit opt-in. No concealed execution, exfiltration, or untrusted remote input is present in the supplied evidence.
Impact: none · Exploitability: unlikely
Developer action: none
- Scanner
- opengrep 1.26.0
- Rule
- tavernkeeper.dynamic-execution.javascript-eval
- File role
- production
- Source
- src/components/nodes/IfNode/definition.ts:87