TavernKeeper Scan Report

NeoTavern/NeoTavern-Frontend

Commit a0d833c Reviewed

No material or immediate-danger concern was identified in this review.

This advisory report describes what the named tools and review process found at one exact commit. Unknown or unobserved behavior may still exist.

0 immediate danger 0 material 49 low

What this review found

No material or immediate-danger item was identified.

Minor cautions

Dependency advisory GHSA-v2wj-q39q-566r:pkg:2da03775dcf45324bfa61d36 applies

Minor caution · low confidence

A tool used during development has a known security issue, but it is not used when the app is running normally. An update is still recommended.

Technical evidence

Scanner reason: OSV-Scanner matched advisory GHSA-v2wj-q39q-566r:pkg:2da03775dcf45324bfa61d36 to a dependency declared by this repository.

Contextual assessment: The project depends on vite@7.2.2, which has a known advisory (GHSA-v2wj-q39q-566r). Vite is a build-time devDependency; the shipped frontend does not expose vite's dev server or middleware at runtime. The supplied evidence does not demonstrate an exploitable path in the production deployment.

Impact: low · Exploitability: unlikely

Developer action: Update vite to a patched version (e.g., 7.2.3 or later) when available.

Scanner
osv-scanner 2.4.0
Rule
GHSA-v2wj-q39q-566r:pkg:2da03775dcf45324bfa61d36
File role
production
Source
package-lock.json

Dependency advisory GHSA-v2hh-gcrm-f6hx:pkg:1c043fdb9ddfee4f4331dbb0 applies

Minor caution · low confidence

A helper library used for data validation has a reported issue, but there is no evidence it can be exploited in this application. Updating is good practice.

Technical evidence

Scanner reason: OSV-Scanner matched advisory GHSA-v2hh-gcrm-f6hx:pkg:1c043fdb9ddfee4f4331dbb0 to a dependency declared by this repository.

Contextual assessment: The transitive dependency fast-uri@3.1.2 (used by ajv) has a known advisory (GHSA-v2hh-gcrm-f6hx). No attacker-controlled input path or concrete exploit scenario is demonstrated by the supplied evidence. The advisory may affect input validation but without demonstrated reachability the risk is low.

Impact: low · Exploitability: unlikely

Developer action: Update fast-uri to a patched version (e.g., 3.1.3 or later) when available.

Scanner
osv-scanner 2.4.0
Rule
GHSA-v2hh-gcrm-f6hx:pkg:1c043fdb9ddfee4f4331dbb0
File role
production
Source
package-lock.json

Dependency advisory GHSA-3jxr-9vmj-r5cp:pkg:387ff1385f57b2b03c5ec3e6 applies

Minor caution · low confidence

A library used for pattern matching has a theoretical flaw, but there is no proof it can be triggered in this project. It is still advisable to update.

Technical evidence

Scanner reason: OSV-Scanner matched advisory GHSA-3jxr-9vmj-r5cp:pkg:387ff1385f57b2b03c5ec3e6 to a dependency declared by this repository.

Contextual assessment: brace-expansion@2.0.3 is a transitive dependency with a known advisory (GHSA-3jxr-9vmj-r5cp). This is typically a ReDoS vulnerability that requires a crafted pattern input. No evidence shows that user-supplied glob patterns reach this library in a way that an attacker can control. The dependency is indirect via dev tools.

Impact: low · Exploitability: unlikely

Developer action: Update brace-expansion to a patched version (e.g., 2.0.5 or later) when available.

Scanner
osv-scanner 2.4.0
Rule
GHSA-3jxr-9vmj-r5cp:pkg:387ff1385f57b2b03c5ec3e6
File role
production
Source
package-lock.json

Dependency advisory GHSA-c2j3-45gr-mqc4:pkg:3a617860720e33c3832a83a7 applies

Minor caution · low confidence

A library that cleans up HTML to prevent attacks has a minor reported issue, but there is no sign it can be exploited in this app. Updating is recommended for safety.

Technical evidence

Scanner reason: OSV-Scanner matched advisory GHSA-c2j3-45gr-mqc4:pkg:3a617860720e33c3832a83a7 to a dependency declared by this repository.

Contextual assessment: dompurify@3.4.11 is a runtime dependency used for HTML sanitization. It has a known low-severity advisory (GHSA-c2j3-45gr-mqc4). The scanner severity is low, and the supplied evidence does not demonstrate an attacker-controlled input path or concrete exploit. Without demonstrated exposure, the risk remains low.

Impact: low · Exploitability: unlikely

Developer action: Update dompurify to version 3.4.12 or later when available.

Scanner
osv-scanner 2.4.0
Rule
GHSA-c2j3-45gr-mqc4:pkg:3a617860720e33c3832a83a7
File role
production
Source
package-lock.json

Dependency advisory GHSA-xvcm-6775-5m9r:pkg:a5026003cd504f00b4f9b2ba applies

Minor caution · low confidence

A data structure library has a reported vulnerability, but there is no indication it can be used against this project. Updating is a good precaution.

Technical evidence

Scanner reason: OSV-Scanner matched advisory GHSA-xvcm-6775-5m9r:pkg:a5026003cd504f00b4f9b2ba to a dependency declared by this repository.

Contextual assessment: immutable@5.1.6 is a transitive dependency with a known advisory (GHSA-xvcm-6775-5m9r). This package is used by some UI libraries. No evidence is provided of a working exploit or attacker-accessible code path. The vulnerability may require specific conditions not present here.

Impact: low · Exploitability: unlikely

Developer action: Update immutable to a patched version (e.g., 5.1.7 or later) when available.

Scanner
osv-scanner 2.4.0
Rule
GHSA-xvcm-6775-5m9r:pkg:a5026003cd504f00b4f9b2ba
File role
production
Source
package-lock.json

Dependency advisory GHSA-rgw5-rvv9-x895:pkg:3f058ee2b68aac4f6bcbbf9e applies

Minor caution · low confidence

An older version of a pattern-matching library has a security notice, but there is no evidence it can be triggered here. Updating is advised.

Technical evidence

Scanner reason: OSV-Scanner matched advisory GHSA-rgw5-rvv9-x895:pkg:3f058ee2b68aac4f6bcbbf9e to a dependency declared by this repository.

Contextual assessment: brace-expansion@1.1.15 is a transitive dependency with a known advisory (GHSA-rgw5-rvv9-x895). Similar to the other brace-expansion advisory, this is a ReDoS issue. No demonstrated input path or attacker control is shown.

Impact: low · Exploitability: unlikely

Developer action: Update brace-expansion to a patched version (e.g., 1.1.16 or later) when available.

Scanner
osv-scanner 2.4.0
Rule
GHSA-rgw5-rvv9-x895:pkg:3f058ee2b68aac4f6bcbbf9e
File role
production
Source
package-lock.json

Dependency advisory GHSA-mh99-v99m-4gvg:pkg:36b5ec528a6a84376d2fa8cc applies

Minor caution · low confidence

Another advisory for the same pattern library; same conclusion as before. No evidence of exploitation.

Technical evidence

Scanner reason: OSV-Scanner matched advisory GHSA-mh99-v99m-4gvg:pkg:36b5ec528a6a84376d2fa8cc to a dependency declared by this repository.

Contextual assessment: brace-expansion@2.0.3 is again flagged under a different advisory (GHSA-mh99-v99m-4gvg). Same reasoning: no demonstrated exploitable path, ReDoS likely not reachable from untrusted input in this project's context.

Impact: low · Exploitability: unlikely

Developer action: Update brace-expansion to a patched version (e.g., 2.0.5 or later) when available.

Scanner
osv-scanner 2.4.0
Rule
GHSA-mh99-v99m-4gvg:pkg:36b5ec528a6a84376d2fa8cc
File role
production
Source
package-lock.json

Dependency advisory GHSA-7p8r-x3mc-p8w7:pkg:678d4d4a8016db80660c8069 applies

Minor caution · low confidence

Another advisory for the same validation library; same reasoning as before. No evidence of exploitability.

Technical evidence

Scanner reason: OSV-Scanner matched advisory GHSA-7p8r-x3mc-p8w7:pkg:678d4d4a8016db80660c8069 to a dependency declared by this repository.

Contextual assessment: fast-uri@3.1.2 is flagged under a second advisory (GHSA-7p8r-x3mc-p8w7). As with the earlier fast-uri advisory, no demonstrated exposure or attacker-controlled path exists in the supplied evidence.

Impact: low · Exploitability: unlikely

Developer action: Update fast-uri to a patched version (e.g., 3.1.3 or later) when available.

Scanner
osv-scanner 2.4.0
Rule
GHSA-7p8r-x3mc-p8w7:pkg:678d4d4a8016db80660c8069
File role
production
Source
package-lock.json

Dependency advisory GHSA-8xcm-r25x-g524:pkg:9efcb22ccad71d16e9fbb4db applies

Minor caution · medium confidence

The project includes a vulnerable version of an HTTP library. We don't know if attackers can actually use it here.

Technical evidence

Scanner reason: OSV-Scanner matched advisory GHSA-8xcm-r25x-g524:pkg:9efcb22ccad71d16e9fbb4db to a dependency declared by this repository.

Contextual assessment: Known vulnerability in undici 7.28.0; no evidence that the vulnerable code path is reachable from attacker-controlled input in this project. Usage of undici (if any) is not shown in the supplied evidence.

Impact: medium · Exploitability: plausible

Developer action: Review if undici is used to handle user-supplied URLs or data. If so, update to a patched version.

Scanner
osv-scanner 2.4.0
Rule
GHSA-8xcm-r25x-g524:pkg:9efcb22ccad71d16e9fbb4db
File role
production
Source
package-lock.json

Dependency advisory GHSA-4cwx-7wf7-3272:pkg:1176429e737cfabdf766cdff applies

Minor caution · medium confidence

Another security issue in the HTTP library. Not confirmed whether it can be exploited here.

Technical evidence

Scanner reason: OSV-Scanner matched advisory GHSA-4cwx-7wf7-3272:pkg:1176429e737cfabdf766cdff to a dependency declared by this repository.

Contextual assessment: High-severity advisory for undici 7.28.0. No demonstrated attacker-controlled input path in the supplied evidence.

Impact: high · Exploitability: plausible

Developer action: Same as previous undici advisory: update if undici is used with untrusted data.

Scanner
osv-scanner 2.4.0
Rule
GHSA-4cwx-7wf7-3272:pkg:1176429e737cfabdf766cdff
File role
production
Source
package-lock.json

Dependency advisory GHSA-m8rv-5g2x-5cg5:pkg:effd824192445928106e41b7 applies

Minor caution · medium confidence

Another undici vulnerability. Not shown to be dangerous here.

Technical evidence

Scanner reason: OSV-Scanner matched advisory GHSA-m8rv-5g2x-5cg5:pkg:effd824192445928106e41b7 to a dependency declared by this repository.

Contextual assessment: Medium-severity undici advisory; no evidence of exploitable usage in this project.

Impact: medium · Exploitability: plausible

Developer action: Update undici to a fixed version if used in runtime network requests.

Scanner
osv-scanner 2.4.0
Rule
GHSA-m8rv-5g2x-5cg5:pkg:effd824192445928106e41b7
File role
production
Source
package-lock.json

Dependency advisory GHSA-mh99-v99m-4gvg:pkg:f395337a0cb5249680cc1cad applies

Minor caution · medium confidence

An old version of a pattern-matching library may have a bug, but it's probably not used in the main app.

Technical evidence

Scanner reason: OSV-Scanner matched advisory GHSA-mh99-v99m-4gvg:pkg:f395337a0cb5249680cc1cad to a dependency declared by this repository.

Contextual assessment: Vulnerability in brace-expansion 1.1.15, likely a transitive dependency of build or test tools. Not expected to be reachable from production runtime.

Impact: low · Exploitability: unlikely

Developer action: Ensure outdated transitive dependency is updated if it appears in production runtime dependencies.

Scanner
osv-scanner 2.4.0
Rule
GHSA-mh99-v99m-4gvg:pkg:f395337a0cb5249680cc1cad
File role
production
Source
package-lock.json

Dependency advisory GHSA-v6wh-96g9-6wx3:pkg:ac373679d1ec0446c126c2b6 applies

Minor caution · high confidence

Vite is only used during development. The vulnerability does not affect the running app.

Technical evidence

Scanner reason: OSV-Scanner matched advisory GHSA-v6wh-96g9-6wx3:pkg:ac373679d1ec0446c126c2b6 to a dependency declared by this repository.

Contextual assessment: Vite 7.2.2 is a development dependency. In production, the built frontend is served statically; the Vite server is not running. Exploitation would require dev-mode runtime, which is not the intended deployment.

Impact: low · Exploitability: unlikely

Developer action: Update Vite for development builds to avoid risks during development.

Scanner
osv-scanner 2.4.0
Rule
GHSA-v6wh-96g9-6wx3:pkg:ac373679d1ec0446c126c2b6
File role
production
Source
package-lock.json

Dependency advisory GHSA-fx2h-pf6j-xcff:pkg:dd82781926efc7ade22030d3 applies

Minor caution · high confidence

This Vite vulnerability also only applies during development.

Technical evidence

Scanner reason: OSV-Scanner matched advisory GHSA-fx2h-pf6j-xcff:pkg:dd82781926efc7ade22030d3 to a dependency declared by this repository.

Contextual assessment: Another Vite advisory; same reasoning – Vite is a dev dependency and not used in production runtime.

Impact: low · Exploitability: unlikely

Developer action: Update Vite to a patched version for development safety.

Scanner
osv-scanner 2.4.0
Rule
GHSA-fx2h-pf6j-xcff:pkg:dd82781926efc7ade22030d3
File role
production
Source
package-lock.json

Dependency advisory GHSA-pm4m-ph32-ghv5:pkg:9fbe9520ff824acfe7c4ed6a applies

Minor caution · medium confidence

The YAML library has a security flaw that could let an attacker run code, but we don't see where attackers could supply malicious YAML.

Technical evidence

Scanner reason: OSV-Scanner matched advisory GHSA-pm4m-ph32-ghv5:pkg:9fbe9520ff824acfe7c4ed6a to a dependency declared by this repository.

Contextual assessment: js-yaml 5.2.1 has a known code injection vulnerability. The project uses js-yaml as a direct dependency (YAML parsing). However, no evidence that attacker-controlled YAML is parsed. If YAML is loaded only from trusted local files, the risk is limited.

Impact: high · Exploitability: plausible

Developer action: Review all locations where js-yaml is used to parse YAML. If any input comes from user-controlled sources, update js-yaml or sanitize input.

Scanner
osv-scanner 2.4.0
Rule
GHSA-pm4m-ph32-ghv5:pkg:9fbe9520ff824acfe7c4ed6a
File role
production
Source
package-lock.json

Dependency advisory GHSA-8r6m-32jq-jx6q:pkg:4103fd8f223da7e70be01de8 applies

Minor caution · medium confidence

The XML parser has a security issue. If the app parses untrusted XML, an attacker could exploit it. Not shown to be the case.

Technical evidence

Scanner reason: OSV-Scanner matched advisory GHSA-8r6m-32jq-jx6q:pkg:4103fd8f223da7e70be01de8 to a dependency declared by this repository.

Contextual assessment: fast-xml-parser 5.9.3 has a known vulnerability. It is a direct dependency used for XML parsing. No demonstrated attacker-controlled XML input path in the supplied evidence.

Impact: high · Exploitability: plausible

Developer action: Audit XML parsing points. If user-supplied or fetched XML is parsed, update fast-xml-parser to a fixed version.

Scanner
osv-scanner 2.4.0
Rule
GHSA-8r6m-32jq-jx6q:pkg:4103fd8f223da7e70be01de8
File role
production
Source
package-lock.json

Dependency advisory GHSA-rgw5-rvv9-x895:pkg:3a2d891c083fd08457b3fe41 applies

Minor caution · medium confidence

The pattern-matching library used during development has a bug, but it doesn't affect the running app.

Technical evidence

Scanner reason: OSV-Scanner matched advisory GHSA-rgw5-rvv9-x895:pkg:3a2d891c083fd08457b3fe41 to a dependency declared by this repository.

Contextual assessment: brace-expansion 2.0.3 is listed as a dev dependency. Vulnerability likely involves ReDoS in pattern matching used in build tools. Not expected to be exploitable in production runtime.

Impact: low · Exploitability: unlikely

Developer action: Update brace-expansion in dev dependencies to avoid issues during development.

Scanner
osv-scanner 2.4.0
Rule
GHSA-rgw5-rvv9-x895:pkg:3a2d891c083fd08457b3fe41
File role
production
Source
package-lock.json

Dependency advisory GHSA-2v37-7h3g-55p8:pkg:32565e5915130b51271b4195 applies

Minor caution · medium confidence

The ID generator library has a security flaw. It might be used to create tokens, but we don't see how it's used here.

Technical evidence

Scanner reason: OSV-Scanner matched advisory GHSA-2v37-7h3g-55p8:pkg:32565e5915130b51271b4195 to a dependency declared by this repository.

Contextual assessment: nanoid 3.3.12 has a vulnerability. nanoid is used for generating unique IDs. If the ID generator is used in a security-sensitive context (e.g., session tokens), there could be risk. No evidence of such usage in the supplied evidence.

Impact: medium · Exploitability: plausible

Developer action: Assess whether nanoid is used for security-critical identifiers. If so, update to a patched version.

Scanner
osv-scanner 2.4.0
Rule
GHSA-2v37-7h3g-55p8:pkg:32565e5915130b51271b4195
File role
production
Source
package-lock.json

Dependency advisory GHSA-55q2-fjhq-7xh7:pkg:2fd628b415ad04f802a2d1cc applies

Minor caution · medium confidence

The HTML sanitizer has a flaw that could allow malicious scripts to slip through. Not known if it's exploited here.

Technical evidence

Scanner reason: OSV-Scanner matched advisory GHSA-55q2-fjhq-7xh7:pkg:2fd628b415ad04f802a2d1cc to a dependency declared by this repository.

Contextual assessment: dompurify 3.4.11 has a known bypass. dompurify is used for sanitizing HTML. If user-generated content is sanitized, an attacker could bypass to inject XSS. No specific evidence of the vulnerability being triggered in this project.

Impact: medium · Exploitability: plausible

Developer action: Update dompurify to the latest version and review sanitization logic for any edge cases.

Scanner
osv-scanner 2.4.0
Rule
GHSA-55q2-fjhq-7xh7:pkg:2fd628b415ad04f802a2d1cc
File role
production
Source
package-lock.json

Dependency advisory GHSA-5p4m-2wfm-xmqj:pkg:d055453f026a4e70572d800d applies

Minor caution · medium confidence

A YAML library used in development tools has a security issue. It doesn't affect the main app.

Technical evidence

Scanner reason: OSV-Scanner matched advisory GHSA-5p4m-2wfm-xmqj:pkg:d055453f026a4e70572d800d to a dependency declared by this repository.

Contextual assessment: js-yaml 4.3.0 (a transitive dependency, often used by eslint or other tools) has a code injection vulnerability. This is likely a dev dependency. Not used in production runtime.

Impact: high · Exploitability: plausible

Developer action: Update the parent dependency that pulls in js-yaml 4.3.0 to avoid the vulnerable version.

Scanner
osv-scanner 2.4.0
Rule
GHSA-5p4m-2wfm-xmqj:pkg:d055453f026a4e70572d800d
File role
production
Source
package-lock.json

Dependency advisory GHSA-fxqj-rqcc-2cmp:pkg:48f7fae3c8c125b98852d2a2 applies

Minor caution · high confidence

The CSS processing tool used during development has a bug. The running app is not affected.

Technical evidence

Scanner reason: OSV-Scanner matched advisory GHSA-fxqj-rqcc-2cmp:pkg:48f7fae3c8c125b98852d2a2 to a dependency declared by this repository.

Contextual assessment: postcss 8.5.16 is a dev dependency used by Vite and other build tools. Vulnerability likely affects CSS parsing in development. Not reachable in production.

Impact: low · Exploitability: unlikely

Developer action: Update postcss in dev dependencies for build safety.

Scanner
osv-scanner 2.4.0
Rule
GHSA-fxqj-rqcc-2cmp:pkg:48f7fae3c8c125b98852d2a2
File role
production
Source
package-lock.json

Dependency advisory GHSA-r28c-9q8g-f849:pkg:97b607f316e1d58c10e4e4eb applies

Minor caution · high confidence

Another CSS tool bug that only affects development.

Technical evidence

Scanner reason: OSV-Scanner matched advisory GHSA-r28c-9q8g-f849:pkg:97b607f316e1d58c10e4e4eb to a dependency declared by this repository.

Contextual assessment: Another postcss advisory; same reasoning – dev-only vulnerability.

Impact: low · Exploitability: unlikely

Developer action: Update postcss to a fixed version.

Scanner
osv-scanner 2.4.0
Rule
GHSA-r28c-9q8g-f849:pkg:97b607f316e1d58c10e4e4eb
File role
production
Source
package-lock.json

Dependency advisory GHSA-p9ff-h696-f583:pkg:4fdb809d17c4d326174c35f0 applies

Minor caution · high confidence

Yet another Vite vulnerability that doesn't affect the running app.

Technical evidence

Scanner reason: OSV-Scanner matched advisory GHSA-p9ff-h696-f583:pkg:4fdb809d17c4d326174c35f0 to a dependency declared by this repository.

Contextual assessment: Vite 7.2.2 advisory (another one). Dev dependency, not used in production.

Impact: low · Exploitability: unlikely

Developer action: Update Vite to latest patch.

Scanner
osv-scanner 2.4.0
Rule
GHSA-p9ff-h696-f583:pkg:4fdb809d17c4d326174c35f0
File role
production
Source
package-lock.json

Dependency advisory GHSA-v3r7-h72x-cjcm:pkg:2f99006f4e2ddba635fa3089 applies

Minor caution · medium confidence

Another HTTP library vulnerability. Not shown to be exploitable here.

Technical evidence

Scanner reason: OSV-Scanner matched advisory GHSA-v3r7-h72x-cjcm:pkg:2f99006f4e2ddba635fa3089 to a dependency declared by this repository.

Contextual assessment: undici 7.28.0 advisory (medium). Same as previous undici findings – no demonstrated exploit path.

Impact: medium · Exploitability: plausible

Developer action: Same as other undici advisories: update if used with untrusted data.

Scanner
osv-scanner 2.4.0
Rule
GHSA-v3r7-h72x-cjcm:pkg:2f99006f4e2ddba635fa3089
File role
production
Source
package-lock.json

Dependency advisory GHSA-v56q-mh7h-f735:pkg:95da09a06d8bd82445831b2f applies

Minor caution · medium confidence

The project includes an outdated version of a library used for managing data. While it has a known security issue, it's not clear how an attacker could actually use it to cause harm in this app.

Technical evidence

Scanner reason: OSV-Scanner matched advisory GHSA-v56q-mh7h-f735:pkg:95da09a06d8bd82445831b2f to a dependency declared by this repository.

Contextual assessment: immutable@5.1.6 is a transitive dependency with a known advisory. No evidence that the vulnerable code is reachable from attacker-controlled input in this frontend project. The npm advisory may be for server-side or unrealistic scenarios. Without demonstrated runtime exposure, the risk is minimal.

Impact: low · Exploitability: unlikely

Developer action: Update immutable to a patched version if it is a direct dependency; otherwise, run npm audit and update lockfile.

Scanner
osv-scanner 2.4.0
Rule
GHSA-v56q-mh7h-f735:pkg:95da09a06d8bd82445831b2f
File role
production
Source
package-lock.json

Dependency advisory GHSA-3jxr-9vmj-r5cp:pkg:33bd75a43666b34e8d957c42 applies

Minor caution · medium confidence

An old version of a text pattern library is included. It has a bug that could cause slowdowns, but only in very specific conditions that don't apply here.

Technical evidence

Scanner reason: OSV-Scanner matched advisory GHSA-3jxr-9vmj-r5cp:pkg:33bd75a43666b34e8d957c42 to a dependency declared by this repository.

Contextual assessment: brace-expansion@1.1.15 is an old version likely used by dev tooling. The advisory (GHSA-3jxr-9vmj-r5cp) is for a regex denial-of-service that requires attacker control over brace patterns. In frontend build scripts this is not exploitable from user input. No demonstrated runtime path.

Impact: low · Exploitability: unlikely

Developer action: Update to a newer version of brace-expansion if it is a direct dependency; otherwise, update the lockfile via npm audit fix.

Scanner
osv-scanner 2.4.0
Rule
GHSA-3jxr-9vmj-r5cp:pkg:33bd75a43666b34e8d957c42
File role
production
Source
package-lock.json

Dependency advisory GHSA-28wg-ghj8-5hjv:pkg:d681b9f3617b82bd6b835445 applies

Minor caution · medium confidence

A small library for creating random IDs is outdated. The vulnerability might make IDs slightly guessable, but this app doesn't use them for anything sensitive.

Technical evidence

Scanner reason: OSV-Scanner matched advisory GHSA-28wg-ghj8-5hjv:pkg:d681b9f3617b82bd6b835445 to a dependency declared by this repository.

Contextual assessment: nanoid@3.3.12 is a library for generating unique IDs. The advisory (GHSA-28wg-ghj8-5hjv) relates to predictability or collision issues. In this frontend, nanoid is likely used for UI keys or temporary IDs. Even if predictable, the impact is limited to minor information disclosure or state confusion. No attacker control over ID generation is demonstrated.

Impact: low · Exploitability: unlikely

Developer action: Update nanoid to version 3.3.13 or later.

Scanner
osv-scanner 2.4.0
Rule
GHSA-28wg-ghj8-5hjv:pkg:d681b9f3617b82bd6b835445
File role
production
Source
package-lock.json

Dependency advisory GHSA-4c8g-83qw-93j6:pkg:a90c096b0a189e0f49499767 applies

Minor caution · medium confidence

A library that handles web addresses has a bug. It's buried deep in the dependencies and not directly used by the app's features.

Technical evidence

Scanner reason: OSV-Scanner matched advisory GHSA-4c8g-83qw-93j6:pkg:a90c096b0a189e0f49499767 to a dependency declared by this repository.

Contextual assessment: fast-uri@3.1.2 is a URI parsing library. The advisory (GHSA-4c8g-83qw-93j6) may cause denial of service or incorrect parsing. In this frontend, fast-uri is a transitive dependency of express or other server components. Without evidence that attacker-controlled URIs are parsed by this vulnerable code path, exposure is not demonstrated.

Impact: low · Exploitability: unlikely

Developer action: Update fast-uri to a patched version.

Scanner
osv-scanner 2.4.0
Rule
GHSA-4c8g-83qw-93j6:pkg:a90c096b0a189e0f49499767
File role
production
Source
package-lock.json

Dependency advisory GHSA-4w7w-66w2-5vf9:pkg:cdcea1ddcbe6ed9555aaec70 applies

Minor caution · medium confidence

The build tool used to create the app has a security notice. Since it's only used during development and not when running the app, it's not a concern for users.

Technical evidence

Scanner reason: OSV-Scanner matched advisory GHSA-4w7w-66w2-5vf9:pkg:cdcea1ddcbe6ed9555aaec70 to a dependency declared by this repository.

Contextual assessment: vite@7.2.2 is a build tool listed as a devDependency. The advisory (GHSA-4w7w-66w2-5vf9) likely affects development server or build process. It does not affect production runtime. No attacker can exploit this unless they have local access during development, which is not a realistic threat model for end users.

Impact: low · Exploitability: unlikely

Developer action: Update vite to version 7.2.3 or later.

Scanner
osv-scanner 2.4.0
Rule
GHSA-4w7w-66w2-5vf9:pkg:cdcea1ddcbe6ed9555aaec70
File role
production
Source
package-lock.json

Dependency advisory GHSA-mh99-v99m-4gvg:pkg:17a4bca76c8dccd42bb43bfa applies

Minor caution · medium confidence

Another version of the text pattern library has a bug that could slow things down, but it's not reachable by attackers.

Technical evidence

Scanner reason: OSV-Scanner matched advisory GHSA-mh99-v99m-4gvg:pkg:17a4bca76c8dccd42bb43bfa to a dependency declared by this repository.

Contextual assessment: brace-expansion@5.0.7 is a newer version used by some dependency. The advisory (GHSA-mh99-v99m-4gvg) is a regex denial of service. As with the older version, no demonstrated attacker-controlled path in production use.

Impact: low · Exploitability: unlikely

Developer action: Update to a patched version of brace-expansion.

Scanner
osv-scanner 2.4.0
Rule
GHSA-mh99-v99m-4gvg:pkg:17a4bca76c8dccd42bb43bfa
File role
production
Source
package-lock.json

Dependency advisory GHSA-jr45-8vmc-qm54:pkg:ef6cbe09bba3516afec0221f applies

Minor caution · medium confidence

The server part of the app uses an outdated networking library. While it could be exploited if someone sends malicious network traffic, the app only listens on your own computer, making it very hard for an attacker to reach.

Technical evidence

Scanner reason: OSV-Scanner matched advisory GHSA-jr45-8vmc-qm54:pkg:ef6cbe09bba3516afec0221f to a dependency declared by this repository.

Contextual assessment: undici@7.28.0 is an HTTP client used by the Node.js server (express is a production dependency). The advisory (GHSA-jr45-8vmc-qm54) could allow HTTP request smuggling or other network-level attacks. However, the server listens only on localhost by default, reducing the attack surface. No evidence that attacker-controlled traffic reaches the vulnerable component in this configuration. Exposure is not demonstrated.

Impact: low · Exploitability: plausible

Developer action: Update undici to a patched version (7.28.1 or later) and review server configuration.

Scanner
osv-scanner 2.4.0
Rule
GHSA-jr45-8vmc-qm54:pkg:ef6cbe09bba3516afec0221f
File role
production
Source
package-lock.json

Dependency advisory GHSA-rgw5-rvv9-x895:pkg:c15eeb4b6498ad284f4ce31d applies

Minor caution · medium confidence

Another bug in the same library. Still not reachable by attackers.

Technical evidence

Scanner reason: OSV-Scanner matched advisory GHSA-rgw5-rvv9-x895:pkg:c15eeb4b6498ad284f4ce31d to a dependency declared by this repository.

Contextual assessment: Another advisory for brace-expansion@5.0.7 (GHSA-rgw5-rvv9-x895). Same package, different vulnerability. No demonstrated exposure.

Impact: low · Exploitability: unlikely

Developer action: Update brace-expansion to a version that fixes both advisories.

Scanner
osv-scanner 2.4.0
Rule
GHSA-rgw5-rvv9-x895:pkg:c15eeb4b6498ad284f4ce31d
File role
production
Source
package-lock.json
Deterministic technical evidence (5)
  • JavaScript analysis reported javascript.xray.serialize-environment · javascript-analysis webcrack-2.16.0_js-x-ray-16.0.0_signatures-1_literals-1_families-1

    This technical signal is not part of the shipped runtime behavior.

    Policy reason: javascript-xray-inert-tooling · Execution scope: tooling-only

    Source: vite.config.ts:79

  • JavaScript analysis reported javascript.xray.serialize-environment · javascript-analysis webcrack-2.16.0_js-x-ray-16.0.0_signatures-1_literals-1_families-1

    This technical signal is not part of the shipped runtime behavior.

    Policy reason: javascript-xray-inert-tooling · Execution scope: tooling-only

    Source: scripts/build-profile.js:4

  • JavaScript analysis reported javascript.xray.unsafe-command · javascript-analysis webcrack-2.16.0_js-x-ray-16.0.0_signatures-1_literals-1_families-1

    This technical signal is not part of the shipped runtime behavior.

    Policy reason: javascript-xray-inert-tooling · Execution scope: tooling-only

    Source: scripts/build-profile.js:8-12

  • JavaScript analysis reported javascript.xray.shady-link · javascript-analysis webcrack-2.16.0_js-x-ray-16.0.0_signatures-1_literals-1_families-1

    This technical signal is not part of the shipped runtime behavior.

    Policy reason: javascript-xray-inert-tooling · Execution scope: tooling-only

    Source: vite.config.ts:32

  • JavaScript analysis reported javascript.xray.data-exfiltration · javascript-analysis webcrack-2.16.0_js-x-ray-16.0.0_signatures-1_literals-1_families-1

    This technical signal is not part of the shipped runtime behavior.

    Policy reason: javascript-xray-inert-tooling · Execution scope: tooling-only

    Source: vite.config.ts:3

Contextual expected matches (12)

OpenGrep reported tavernkeeper.persistence.startup-modification

Expected behavior · high confidence

The security tool flagged a line of CSS styling as a startup modification, but it's just a style rule for arranging buttons, not any actual code that runs.

Technical evidence

Scanner reason: OpenGrep matched static-analysis rule tavernkeeper.persistence.startup-modification in this repository.

Contextual assessment: The scanner matched a 'startup-modification' rule on CSS class selector .profile-actions at line 473, which is within a scoped style block. This line defines visual layout, not runtime logic. No startup persistence behavior exists.

Impact: none · Exploitability: unlikely

Developer action: none

Scanner
opengrep 1.26.0
Rule
tavernkeeper.persistence.startup-modification
File role
production
Source
src/extensions/built-in/model-randomizer/SettingsPanel.vue:473

JavaScript analysis reported javascript.xray.unsafe-command

Expected behavior · high confidence

The launcher runs a git command to check the current version, which is needed for automatic updates. The command is fixed and cannot be altered by an attacker.

Technical evidence

Scanner reason: JavaScript analysis matched static JavaScript security signal javascript.xray.unsafe-command in this repository.

Contextual assessment: The execSync call at line 162 runs 'git rev-parse HEAD' to obtain the current commit hash for cache invalidation. The command argument is a hardcoded string with no user input interpolation. This is legitimate behavior for a launcher that manages git-based project updates.

Impact: none · Exploitability: unlikely

Developer action: none

Scanner
javascript-analysis webcrack-2.16.0_js-x-ray-16.0.0_signatures-1_literals-1_families-1
Rule
javascript.xray.unsafe-command
File role
production
Source
launcher.js:162

OpenGrep reported tavernkeeper.persistence.startup-modification

Expected behavior · high confidence

The security tool flagged a line of CSS styling as a startup modification, but it's just a style rule for a profile management section, not any actual code that runs.

Technical evidence

Scanner reason: OpenGrep matched static-analysis rule tavernkeeper.persistence.startup-modification in this repository.

Contextual assessment: The scanner matched a 'startup-modification' rule on CSS class selector .profile-management at line 458, which is within a scoped style block. This line defines visual layout, not runtime logic. No startup persistence behavior occurs.

Impact: none · Exploitability: unlikely

Developer action: none

Scanner
opengrep 1.26.0
Rule
tavernkeeper.persistence.startup-modification
File role
production
Source
src/extensions/built-in/model-randomizer/SettingsPanel.vue:458

OpenGrep reported tavernkeeper.persistence.startup-modification

Expected behavior · high confidence

The security tool flagged a line of CSS styling as a startup modification, but it's just a style rule for a content area, not any actual code that runs.

Technical evidence

Scanner reason: OpenGrep matched static-analysis rule tavernkeeper.persistence.startup-modification in this repository.

Contextual assessment: The scanner matched a 'startup-modification' rule on CSS class selector .profile-content at line 479, which is within a scoped style block. This line defines visual layout, not runtime logic. No startup persistence behavior exists.

Impact: none · Exploitability: unlikely

Developer action: none

Scanner
opengrep 1.26.0
Rule
tavernkeeper.persistence.startup-modification
File role
production
Source
src/extensions/built-in/model-randomizer/SettingsPanel.vue:479

JavaScript analysis reported javascript.xray.shady-link

Expected behavior · high confidence

The launcher has a list of official website addresses that it uses to download the backend. These are fixed and safe.

Technical evidence

Scanner reason: JavaScript analysis matched static JavaScript security signal javascript.xray.shady-link in this repository.

Contextual assessment: The URLs in REPO_URLS point to the official SillyTavern and NeoTavern GitHub repositories. These are hardcoded, not user-supplied, and are used for cloning the backend and plugin. No dynamic or user-controlled redirection is present.

Impact: none · Exploitability: unlikely

Developer action: none

Scanner
javascript-analysis webcrack-2.16.0_js-x-ray-16.0.0_signatures-1_literals-1_families-1
Rule
javascript.xray.shady-link
File role
production
Source
launcher.js:31

JavaScript analysis reported javascript.xray.serialize-environment

Expected behavior · high confidence

The security tool flagged a line that reads an environment variable while building the app. The variable is only the project version number and is used to add a version label to the generated code, which is normal and harmless.

Technical evidence

Scanner reason: JavaScript analysis matched static JavaScript security signal javascript.xray.serialize-environment in this repository.

Contextual assessment: The scanner flagged usage of process.env at line 18 in a Vite build config. This reads the benign npm_package_version environment variable to embed a version comment in generated TypeScript declaration files. No credentials or secrets are accessed or exfiltrated. This is standard build-time metadata injection.

Impact: none · Exploitability: unlikely

Developer action: none

Scanner
javascript-analysis webcrack-2.16.0_js-x-ray-16.0.0_signatures-1_literals-1_families-1
Rule
javascript.xray.serialize-environment
File role
production
Source
vite.config.types.ts:18

JavaScript analysis reported javascript.xray.serialize-environment

Expected behavior · high confidence

The launcher reads settings from environment variables, which is a common and expected way to configure programs. No secret information is being sent anywhere.

Technical evidence

Scanner reason: JavaScript analysis matched static JavaScript security signal javascript.xray.serialize-environment in this repository.

Contextual assessment: The code reads environment variables (NEO_*) and writes them into the configuration object, which is later saved to disk. This is an intentional override mechanism documented in the project's README. There is no evidence of exfiltration or unintended credential exposure; the config is stored locally.

Impact: none · Exploitability: unlikely

Developer action: none

Scanner
javascript-analysis webcrack-2.16.0_js-x-ray-16.0.0_signatures-1_literals-1_families-1
Rule
javascript.xray.serialize-environment
File role
production
Source
launcher.js:110

Gitleaks reported generic-api-key

Expected behavior · high confidence

A security scanner mistakenly thought a line of code was a leaked password. It's actually just telling the app where to store an API key, not exposing the key itself. This is normal.

Technical evidence

Scanner reason: Gitleaks matched secret-detection rule generic-api-key in this repository.

Contextual assessment: Gitleaks flagged line 169 which contains `{ widget: 'key-manager', label: 'apiConnections.ai21Key', secretKey: SECRET_KEYS.AI21 }`. This is a UI configuration object that references a constant name for managing AI21 API keys. It does not contain an actual credential. The pattern 'secretKey' with a constant value triggered the scanner. This is expected behavior for a SillyTavern frontend that handles API key management.

Impact: none · Exploitability: unlikely

Developer action: none

Scanner
gitleaks 8.30.1
Rule
generic-api-key
File role
production
Source
src/api-connection-definition.ts:169

OpenGrep reported tavernkeeper.persistence.startup-modification

Expected behavior · high confidence

The security tool flagged a line of CSS styling as a startup modification, but it's just a style rule for arranging profile rows, not any actual code that runs.

Technical evidence

Scanner reason: OpenGrep matched static-analysis rule tavernkeeper.persistence.startup-modification in this repository.

Contextual assessment: The scanner matched a 'startup-modification' rule on CSS class selector .profile-row at line 304, which is within a scoped style block. This line defines visual layout for profile rows, not runtime logic. No startup persistence behavior exists.

Impact: none · Exploitability: unlikely

Developer action: none

Scanner
opengrep 1.26.0
Rule
tavernkeeper.persistence.startup-modification
File role
production
Source
src/extensions/built-in/mythic-agents/components/NpcTab.vue:304

Gitleaks reported generic-api-key

Expected behavior · high confidence

The scanner thought a line of code might contain a password, but it's just a placeholder pointing to where the real password will be stored. No actual password is exposed.

Technical evidence

Scanner reason: Gitleaks matched secret-detection rule generic-api-key in this repository.

Contextual assessment: Gitleaks flagged a reference to the constant SECRET_KEYS.AI21 in a UI configuration object. This is a symbolic key reference, not an actual credential. The code defines API key input fields using a key-manager widget and a secretKey constant, which is legitimate and expected behavior for an AI frontend that manages multiple provider keys.

Impact: none · Exploitability: unlikely

Developer action: none

Scanner
gitleaks 8.30.1
Rule
generic-api-key
File role
production
Source
src/api-connection-definition.ts:169

OpenGrep reported tavernkeeper.persistence.startup-modification

Expected behavior · high confidence

A security scanner thought a CSS style was suspicious. It's just styling for a popup window. The app saves your settings normally, like any other app.

Technical evidence

Scanner reason: OpenGrep matched static-analysis rule tavernkeeper.persistence.startup-modification in this repository.

Contextual assessment: OpenGrep flagged line 109 in MemoryPopup.vue with a rule 'tavernkeeper.persistence.startup-modification'. The flagged line is `.profile-section {` in a CSS block. The component uses standard Vue lifecycle (onMounted) to load settings and watch to save user preferences. This is normal UI persistence, not malicious startup modification. The scanner rule appears to have a false positive on this line.

Impact: none · Exploitability: unlikely

Developer action: none

Scanner
opengrep 1.26.0
Rule
tavernkeeper.persistence.startup-modification
File role
production
Source
src/extensions/built-in/chat-memory/MemoryPopup.vue:109

OpenGrep reported tavernkeeper.persistence.startup-modification

Expected behavior · high confidence

The security tool flagged a line of CSS styling as a startup modification, but it's just a style rule for control buttons, not any actual code that runs.

Technical evidence

Scanner reason: OpenGrep matched static-analysis rule tavernkeeper.persistence.startup-modification in this repository.

Contextual assessment: The scanner matched a 'startup-modification' rule on CSS class selector .profile-controls at line 464, which is within a scoped style block. This line defines visual layout, not runtime logic. No startup persistence behavior occurs.

Impact: none · Exploitability: unlikely

Developer action: none

Scanner
opengrep 1.26.0
Rule
tavernkeeper.persistence.startup-modification
File role
production
Source
src/extensions/built-in/model-randomizer/SettingsPanel.vue:464

Coverage and limitations

JavaScript coverage

Unresolved JavaScript stages

Tools

Limitations

Technical scan identity