What this review found
No material or immediate-danger item was identified.
Minor cautions
Dependency advisory GHSA-v2wj-q39q-566r:pkg:2da03775dcf45324bfa61d36 applies
Minor caution · low confidence
A tool used during development has a known security issue, but it is not used when the app is running normally. An update is still recommended.
Technical evidence
Scanner reason: OSV-Scanner matched advisory GHSA-v2wj-q39q-566r:pkg:2da03775dcf45324bfa61d36 to a dependency declared by this repository.
Contextual assessment: The project depends on vite@7.2.2, which has a known advisory (GHSA-v2wj-q39q-566r). Vite is a build-time devDependency; the shipped frontend does not expose vite's dev server or middleware at runtime. The supplied evidence does not demonstrate an exploitable path in the production deployment.
Impact: low · Exploitability: unlikely
Developer action: Update vite to a patched version (e.g., 7.2.3 or later) when available.
- Scanner
- osv-scanner 2.4.0
- Rule
- GHSA-v2wj-q39q-566r:pkg:2da03775dcf45324bfa61d36
- File role
- production
- Source
- package-lock.json
Dependency advisory GHSA-v2hh-gcrm-f6hx:pkg:1c043fdb9ddfee4f4331dbb0 applies
Minor caution · low confidence
A helper library used for data validation has a reported issue, but there is no evidence it can be exploited in this application. Updating is good practice.
Technical evidence
Scanner reason: OSV-Scanner matched advisory GHSA-v2hh-gcrm-f6hx:pkg:1c043fdb9ddfee4f4331dbb0 to a dependency declared by this repository.
Contextual assessment: The transitive dependency fast-uri@3.1.2 (used by ajv) has a known advisory (GHSA-v2hh-gcrm-f6hx). No attacker-controlled input path or concrete exploit scenario is demonstrated by the supplied evidence. The advisory may affect input validation but without demonstrated reachability the risk is low.
Impact: low · Exploitability: unlikely
Developer action: Update fast-uri to a patched version (e.g., 3.1.3 or later) when available.
- Scanner
- osv-scanner 2.4.0
- Rule
- GHSA-v2hh-gcrm-f6hx:pkg:1c043fdb9ddfee4f4331dbb0
- File role
- production
- Source
- package-lock.json
Dependency advisory GHSA-3jxr-9vmj-r5cp:pkg:387ff1385f57b2b03c5ec3e6 applies
Minor caution · low confidence
A library used for pattern matching has a theoretical flaw, but there is no proof it can be triggered in this project. It is still advisable to update.
Technical evidence
Scanner reason: OSV-Scanner matched advisory GHSA-3jxr-9vmj-r5cp:pkg:387ff1385f57b2b03c5ec3e6 to a dependency declared by this repository.
Contextual assessment: brace-expansion@2.0.3 is a transitive dependency with a known advisory (GHSA-3jxr-9vmj-r5cp). This is typically a ReDoS vulnerability that requires a crafted pattern input. No evidence shows that user-supplied glob patterns reach this library in a way that an attacker can control. The dependency is indirect via dev tools.
Impact: low · Exploitability: unlikely
Developer action: Update brace-expansion to a patched version (e.g., 2.0.5 or later) when available.
- Scanner
- osv-scanner 2.4.0
- Rule
- GHSA-3jxr-9vmj-r5cp:pkg:387ff1385f57b2b03c5ec3e6
- File role
- production
- Source
- package-lock.json
Dependency advisory GHSA-c2j3-45gr-mqc4:pkg:3a617860720e33c3832a83a7 applies
Minor caution · low confidence
A library that cleans up HTML to prevent attacks has a minor reported issue, but there is no sign it can be exploited in this app. Updating is recommended for safety.
Technical evidence
Scanner reason: OSV-Scanner matched advisory GHSA-c2j3-45gr-mqc4:pkg:3a617860720e33c3832a83a7 to a dependency declared by this repository.
Contextual assessment: dompurify@3.4.11 is a runtime dependency used for HTML sanitization. It has a known low-severity advisory (GHSA-c2j3-45gr-mqc4). The scanner severity is low, and the supplied evidence does not demonstrate an attacker-controlled input path or concrete exploit. Without demonstrated exposure, the risk remains low.
Impact: low · Exploitability: unlikely
Developer action: Update dompurify to version 3.4.12 or later when available.
- Scanner
- osv-scanner 2.4.0
- Rule
- GHSA-c2j3-45gr-mqc4:pkg:3a617860720e33c3832a83a7
- File role
- production
- Source
- package-lock.json
Dependency advisory GHSA-xvcm-6775-5m9r:pkg:a5026003cd504f00b4f9b2ba applies
Minor caution · low confidence
A data structure library has a reported vulnerability, but there is no indication it can be used against this project. Updating is a good precaution.
Technical evidence
Scanner reason: OSV-Scanner matched advisory GHSA-xvcm-6775-5m9r:pkg:a5026003cd504f00b4f9b2ba to a dependency declared by this repository.
Contextual assessment: immutable@5.1.6 is a transitive dependency with a known advisory (GHSA-xvcm-6775-5m9r). This package is used by some UI libraries. No evidence is provided of a working exploit or attacker-accessible code path. The vulnerability may require specific conditions not present here.
Impact: low · Exploitability: unlikely
Developer action: Update immutable to a patched version (e.g., 5.1.7 or later) when available.
- Scanner
- osv-scanner 2.4.0
- Rule
- GHSA-xvcm-6775-5m9r:pkg:a5026003cd504f00b4f9b2ba
- File role
- production
- Source
- package-lock.json
Dependency advisory GHSA-rgw5-rvv9-x895:pkg:3f058ee2b68aac4f6bcbbf9e applies
Minor caution · low confidence
An older version of a pattern-matching library has a security notice, but there is no evidence it can be triggered here. Updating is advised.
Technical evidence
Scanner reason: OSV-Scanner matched advisory GHSA-rgw5-rvv9-x895:pkg:3f058ee2b68aac4f6bcbbf9e to a dependency declared by this repository.
Contextual assessment: brace-expansion@1.1.15 is a transitive dependency with a known advisory (GHSA-rgw5-rvv9-x895). Similar to the other brace-expansion advisory, this is a ReDoS issue. No demonstrated input path or attacker control is shown.
Impact: low · Exploitability: unlikely
Developer action: Update brace-expansion to a patched version (e.g., 1.1.16 or later) when available.
- Scanner
- osv-scanner 2.4.0
- Rule
- GHSA-rgw5-rvv9-x895:pkg:3f058ee2b68aac4f6bcbbf9e
- File role
- production
- Source
- package-lock.json
Dependency advisory GHSA-mh99-v99m-4gvg:pkg:36b5ec528a6a84376d2fa8cc applies
Minor caution · low confidence
Another advisory for the same pattern library; same conclusion as before. No evidence of exploitation.
Technical evidence
Scanner reason: OSV-Scanner matched advisory GHSA-mh99-v99m-4gvg:pkg:36b5ec528a6a84376d2fa8cc to a dependency declared by this repository.
Contextual assessment: brace-expansion@2.0.3 is again flagged under a different advisory (GHSA-mh99-v99m-4gvg). Same reasoning: no demonstrated exploitable path, ReDoS likely not reachable from untrusted input in this project's context.
Impact: low · Exploitability: unlikely
Developer action: Update brace-expansion to a patched version (e.g., 2.0.5 or later) when available.
- Scanner
- osv-scanner 2.4.0
- Rule
- GHSA-mh99-v99m-4gvg:pkg:36b5ec528a6a84376d2fa8cc
- File role
- production
- Source
- package-lock.json
Dependency advisory GHSA-7p8r-x3mc-p8w7:pkg:678d4d4a8016db80660c8069 applies
Minor caution · low confidence
Another advisory for the same validation library; same reasoning as before. No evidence of exploitability.
Technical evidence
Scanner reason: OSV-Scanner matched advisory GHSA-7p8r-x3mc-p8w7:pkg:678d4d4a8016db80660c8069 to a dependency declared by this repository.
Contextual assessment: fast-uri@3.1.2 is flagged under a second advisory (GHSA-7p8r-x3mc-p8w7). As with the earlier fast-uri advisory, no demonstrated exposure or attacker-controlled path exists in the supplied evidence.
Impact: low · Exploitability: unlikely
Developer action: Update fast-uri to a patched version (e.g., 3.1.3 or later) when available.
- Scanner
- osv-scanner 2.4.0
- Rule
- GHSA-7p8r-x3mc-p8w7:pkg:678d4d4a8016db80660c8069
- File role
- production
- Source
- package-lock.json
Dependency advisory GHSA-8xcm-r25x-g524:pkg:9efcb22ccad71d16e9fbb4db applies
Minor caution · medium confidence
The project includes a vulnerable version of an HTTP library. We don't know if attackers can actually use it here.
Technical evidence
Scanner reason: OSV-Scanner matched advisory GHSA-8xcm-r25x-g524:pkg:9efcb22ccad71d16e9fbb4db to a dependency declared by this repository.
Contextual assessment: Known vulnerability in undici 7.28.0; no evidence that the vulnerable code path is reachable from attacker-controlled input in this project. Usage of undici (if any) is not shown in the supplied evidence.
Impact: medium · Exploitability: plausible
Developer action: Review if undici is used to handle user-supplied URLs or data. If so, update to a patched version.
- Scanner
- osv-scanner 2.4.0
- Rule
- GHSA-8xcm-r25x-g524:pkg:9efcb22ccad71d16e9fbb4db
- File role
- production
- Source
- package-lock.json
Dependency advisory GHSA-4cwx-7wf7-3272:pkg:1176429e737cfabdf766cdff applies
Minor caution · medium confidence
Another security issue in the HTTP library. Not confirmed whether it can be exploited here.
Technical evidence
Scanner reason: OSV-Scanner matched advisory GHSA-4cwx-7wf7-3272:pkg:1176429e737cfabdf766cdff to a dependency declared by this repository.
Contextual assessment: High-severity advisory for undici 7.28.0. No demonstrated attacker-controlled input path in the supplied evidence.
Impact: high · Exploitability: plausible
Developer action: Same as previous undici advisory: update if undici is used with untrusted data.
- Scanner
- osv-scanner 2.4.0
- Rule
- GHSA-4cwx-7wf7-3272:pkg:1176429e737cfabdf766cdff
- File role
- production
- Source
- package-lock.json
Dependency advisory GHSA-m8rv-5g2x-5cg5:pkg:effd824192445928106e41b7 applies
Minor caution · medium confidence
Another undici vulnerability. Not shown to be dangerous here.
Technical evidence
Scanner reason: OSV-Scanner matched advisory GHSA-m8rv-5g2x-5cg5:pkg:effd824192445928106e41b7 to a dependency declared by this repository.
Contextual assessment: Medium-severity undici advisory; no evidence of exploitable usage in this project.
Impact: medium · Exploitability: plausible
Developer action: Update undici to a fixed version if used in runtime network requests.
- Scanner
- osv-scanner 2.4.0
- Rule
- GHSA-m8rv-5g2x-5cg5:pkg:effd824192445928106e41b7
- File role
- production
- Source
- package-lock.json
Dependency advisory GHSA-mh99-v99m-4gvg:pkg:f395337a0cb5249680cc1cad applies
Minor caution · medium confidence
An old version of a pattern-matching library may have a bug, but it's probably not used in the main app.
Technical evidence
Scanner reason: OSV-Scanner matched advisory GHSA-mh99-v99m-4gvg:pkg:f395337a0cb5249680cc1cad to a dependency declared by this repository.
Contextual assessment: Vulnerability in brace-expansion 1.1.15, likely a transitive dependency of build or test tools. Not expected to be reachable from production runtime.
Impact: low · Exploitability: unlikely
Developer action: Ensure outdated transitive dependency is updated if it appears in production runtime dependencies.
- Scanner
- osv-scanner 2.4.0
- Rule
- GHSA-mh99-v99m-4gvg:pkg:f395337a0cb5249680cc1cad
- File role
- production
- Source
- package-lock.json
Dependency advisory GHSA-v6wh-96g9-6wx3:pkg:ac373679d1ec0446c126c2b6 applies
Minor caution · high confidence
Vite is only used during development. The vulnerability does not affect the running app.
Technical evidence
Scanner reason: OSV-Scanner matched advisory GHSA-v6wh-96g9-6wx3:pkg:ac373679d1ec0446c126c2b6 to a dependency declared by this repository.
Contextual assessment: Vite 7.2.2 is a development dependency. In production, the built frontend is served statically; the Vite server is not running. Exploitation would require dev-mode runtime, which is not the intended deployment.
Impact: low · Exploitability: unlikely
Developer action: Update Vite for development builds to avoid risks during development.
- Scanner
- osv-scanner 2.4.0
- Rule
- GHSA-v6wh-96g9-6wx3:pkg:ac373679d1ec0446c126c2b6
- File role
- production
- Source
- package-lock.json
Dependency advisory GHSA-fx2h-pf6j-xcff:pkg:dd82781926efc7ade22030d3 applies
Minor caution · high confidence
This Vite vulnerability also only applies during development.
Technical evidence
Scanner reason: OSV-Scanner matched advisory GHSA-fx2h-pf6j-xcff:pkg:dd82781926efc7ade22030d3 to a dependency declared by this repository.
Contextual assessment: Another Vite advisory; same reasoning – Vite is a dev dependency and not used in production runtime.
Impact: low · Exploitability: unlikely
Developer action: Update Vite to a patched version for development safety.
- Scanner
- osv-scanner 2.4.0
- Rule
- GHSA-fx2h-pf6j-xcff:pkg:dd82781926efc7ade22030d3
- File role
- production
- Source
- package-lock.json
Dependency advisory GHSA-pm4m-ph32-ghv5:pkg:9fbe9520ff824acfe7c4ed6a applies
Minor caution · medium confidence
The YAML library has a security flaw that could let an attacker run code, but we don't see where attackers could supply malicious YAML.
Technical evidence
Scanner reason: OSV-Scanner matched advisory GHSA-pm4m-ph32-ghv5:pkg:9fbe9520ff824acfe7c4ed6a to a dependency declared by this repository.
Contextual assessment: js-yaml 5.2.1 has a known code injection vulnerability. The project uses js-yaml as a direct dependency (YAML parsing). However, no evidence that attacker-controlled YAML is parsed. If YAML is loaded only from trusted local files, the risk is limited.
Impact: high · Exploitability: plausible
Developer action: Review all locations where js-yaml is used to parse YAML. If any input comes from user-controlled sources, update js-yaml or sanitize input.
- Scanner
- osv-scanner 2.4.0
- Rule
- GHSA-pm4m-ph32-ghv5:pkg:9fbe9520ff824acfe7c4ed6a
- File role
- production
- Source
- package-lock.json
Dependency advisory GHSA-8r6m-32jq-jx6q:pkg:4103fd8f223da7e70be01de8 applies
Minor caution · medium confidence
The XML parser has a security issue. If the app parses untrusted XML, an attacker could exploit it. Not shown to be the case.
Technical evidence
Scanner reason: OSV-Scanner matched advisory GHSA-8r6m-32jq-jx6q:pkg:4103fd8f223da7e70be01de8 to a dependency declared by this repository.
Contextual assessment: fast-xml-parser 5.9.3 has a known vulnerability. It is a direct dependency used for XML parsing. No demonstrated attacker-controlled XML input path in the supplied evidence.
Impact: high · Exploitability: plausible
Developer action: Audit XML parsing points. If user-supplied or fetched XML is parsed, update fast-xml-parser to a fixed version.
- Scanner
- osv-scanner 2.4.0
- Rule
- GHSA-8r6m-32jq-jx6q:pkg:4103fd8f223da7e70be01de8
- File role
- production
- Source
- package-lock.json
Dependency advisory GHSA-rgw5-rvv9-x895:pkg:3a2d891c083fd08457b3fe41 applies
Minor caution · medium confidence
The pattern-matching library used during development has a bug, but it doesn't affect the running app.
Technical evidence
Scanner reason: OSV-Scanner matched advisory GHSA-rgw5-rvv9-x895:pkg:3a2d891c083fd08457b3fe41 to a dependency declared by this repository.
Contextual assessment: brace-expansion 2.0.3 is listed as a dev dependency. Vulnerability likely involves ReDoS in pattern matching used in build tools. Not expected to be exploitable in production runtime.
Impact: low · Exploitability: unlikely
Developer action: Update brace-expansion in dev dependencies to avoid issues during development.
- Scanner
- osv-scanner 2.4.0
- Rule
- GHSA-rgw5-rvv9-x895:pkg:3a2d891c083fd08457b3fe41
- File role
- production
- Source
- package-lock.json
Dependency advisory GHSA-2v37-7h3g-55p8:pkg:32565e5915130b51271b4195 applies
Minor caution · medium confidence
The ID generator library has a security flaw. It might be used to create tokens, but we don't see how it's used here.
Technical evidence
Scanner reason: OSV-Scanner matched advisory GHSA-2v37-7h3g-55p8:pkg:32565e5915130b51271b4195 to a dependency declared by this repository.
Contextual assessment: nanoid 3.3.12 has a vulnerability. nanoid is used for generating unique IDs. If the ID generator is used in a security-sensitive context (e.g., session tokens), there could be risk. No evidence of such usage in the supplied evidence.
Impact: medium · Exploitability: plausible
Developer action: Assess whether nanoid is used for security-critical identifiers. If so, update to a patched version.
- Scanner
- osv-scanner 2.4.0
- Rule
- GHSA-2v37-7h3g-55p8:pkg:32565e5915130b51271b4195
- File role
- production
- Source
- package-lock.json
Dependency advisory GHSA-55q2-fjhq-7xh7:pkg:2fd628b415ad04f802a2d1cc applies
Minor caution · medium confidence
The HTML sanitizer has a flaw that could allow malicious scripts to slip through. Not known if it's exploited here.
Technical evidence
Scanner reason: OSV-Scanner matched advisory GHSA-55q2-fjhq-7xh7:pkg:2fd628b415ad04f802a2d1cc to a dependency declared by this repository.
Contextual assessment: dompurify 3.4.11 has a known bypass. dompurify is used for sanitizing HTML. If user-generated content is sanitized, an attacker could bypass to inject XSS. No specific evidence of the vulnerability being triggered in this project.
Impact: medium · Exploitability: plausible
Developer action: Update dompurify to the latest version and review sanitization logic for any edge cases.
- Scanner
- osv-scanner 2.4.0
- Rule
- GHSA-55q2-fjhq-7xh7:pkg:2fd628b415ad04f802a2d1cc
- File role
- production
- Source
- package-lock.json
Dependency advisory GHSA-5p4m-2wfm-xmqj:pkg:d055453f026a4e70572d800d applies
Minor caution · medium confidence
A YAML library used in development tools has a security issue. It doesn't affect the main app.
Technical evidence
Scanner reason: OSV-Scanner matched advisory GHSA-5p4m-2wfm-xmqj:pkg:d055453f026a4e70572d800d to a dependency declared by this repository.
Contextual assessment: js-yaml 4.3.0 (a transitive dependency, often used by eslint or other tools) has a code injection vulnerability. This is likely a dev dependency. Not used in production runtime.
Impact: high · Exploitability: plausible
Developer action: Update the parent dependency that pulls in js-yaml 4.3.0 to avoid the vulnerable version.
- Scanner
- osv-scanner 2.4.0
- Rule
- GHSA-5p4m-2wfm-xmqj:pkg:d055453f026a4e70572d800d
- File role
- production
- Source
- package-lock.json
Dependency advisory GHSA-fxqj-rqcc-2cmp:pkg:48f7fae3c8c125b98852d2a2 applies
Minor caution · high confidence
The CSS processing tool used during development has a bug. The running app is not affected.
Technical evidence
Scanner reason: OSV-Scanner matched advisory GHSA-fxqj-rqcc-2cmp:pkg:48f7fae3c8c125b98852d2a2 to a dependency declared by this repository.
Contextual assessment: postcss 8.5.16 is a dev dependency used by Vite and other build tools. Vulnerability likely affects CSS parsing in development. Not reachable in production.
Impact: low · Exploitability: unlikely
Developer action: Update postcss in dev dependencies for build safety.
- Scanner
- osv-scanner 2.4.0
- Rule
- GHSA-fxqj-rqcc-2cmp:pkg:48f7fae3c8c125b98852d2a2
- File role
- production
- Source
- package-lock.json
Dependency advisory GHSA-r28c-9q8g-f849:pkg:97b607f316e1d58c10e4e4eb applies
Minor caution · high confidence
Another CSS tool bug that only affects development.
Technical evidence
Scanner reason: OSV-Scanner matched advisory GHSA-r28c-9q8g-f849:pkg:97b607f316e1d58c10e4e4eb to a dependency declared by this repository.
Contextual assessment: Another postcss advisory; same reasoning – dev-only vulnerability.
Impact: low · Exploitability: unlikely
Developer action: Update postcss to a fixed version.
- Scanner
- osv-scanner 2.4.0
- Rule
- GHSA-r28c-9q8g-f849:pkg:97b607f316e1d58c10e4e4eb
- File role
- production
- Source
- package-lock.json
Dependency advisory GHSA-p9ff-h696-f583:pkg:4fdb809d17c4d326174c35f0 applies
Minor caution · high confidence
Yet another Vite vulnerability that doesn't affect the running app.
Technical evidence
Scanner reason: OSV-Scanner matched advisory GHSA-p9ff-h696-f583:pkg:4fdb809d17c4d326174c35f0 to a dependency declared by this repository.
Contextual assessment: Vite 7.2.2 advisory (another one). Dev dependency, not used in production.
Impact: low · Exploitability: unlikely
Developer action: Update Vite to latest patch.
- Scanner
- osv-scanner 2.4.0
- Rule
- GHSA-p9ff-h696-f583:pkg:4fdb809d17c4d326174c35f0
- File role
- production
- Source
- package-lock.json
Dependency advisory GHSA-v3r7-h72x-cjcm:pkg:2f99006f4e2ddba635fa3089 applies
Minor caution · medium confidence
Another HTTP library vulnerability. Not shown to be exploitable here.
Technical evidence
Scanner reason: OSV-Scanner matched advisory GHSA-v3r7-h72x-cjcm:pkg:2f99006f4e2ddba635fa3089 to a dependency declared by this repository.
Contextual assessment: undici 7.28.0 advisory (medium). Same as previous undici findings – no demonstrated exploit path.
Impact: medium · Exploitability: plausible
Developer action: Same as other undici advisories: update if used with untrusted data.
- Scanner
- osv-scanner 2.4.0
- Rule
- GHSA-v3r7-h72x-cjcm:pkg:2f99006f4e2ddba635fa3089
- File role
- production
- Source
- package-lock.json
Dependency advisory GHSA-v56q-mh7h-f735:pkg:95da09a06d8bd82445831b2f applies
Minor caution · medium confidence
The project includes an outdated version of a library used for managing data. While it has a known security issue, it's not clear how an attacker could actually use it to cause harm in this app.
Technical evidence
Scanner reason: OSV-Scanner matched advisory GHSA-v56q-mh7h-f735:pkg:95da09a06d8bd82445831b2f to a dependency declared by this repository.
Contextual assessment: immutable@5.1.6 is a transitive dependency with a known advisory. No evidence that the vulnerable code is reachable from attacker-controlled input in this frontend project. The npm advisory may be for server-side or unrealistic scenarios. Without demonstrated runtime exposure, the risk is minimal.
Impact: low · Exploitability: unlikely
Developer action: Update immutable to a patched version if it is a direct dependency; otherwise, run npm audit and update lockfile.
- Scanner
- osv-scanner 2.4.0
- Rule
- GHSA-v56q-mh7h-f735:pkg:95da09a06d8bd82445831b2f
- File role
- production
- Source
- package-lock.json
Dependency advisory GHSA-3jxr-9vmj-r5cp:pkg:33bd75a43666b34e8d957c42 applies
Minor caution · medium confidence
An old version of a text pattern library is included. It has a bug that could cause slowdowns, but only in very specific conditions that don't apply here.
Technical evidence
Scanner reason: OSV-Scanner matched advisory GHSA-3jxr-9vmj-r5cp:pkg:33bd75a43666b34e8d957c42 to a dependency declared by this repository.
Contextual assessment: brace-expansion@1.1.15 is an old version likely used by dev tooling. The advisory (GHSA-3jxr-9vmj-r5cp) is for a regex denial-of-service that requires attacker control over brace patterns. In frontend build scripts this is not exploitable from user input. No demonstrated runtime path.
Impact: low · Exploitability: unlikely
Developer action: Update to a newer version of brace-expansion if it is a direct dependency; otherwise, update the lockfile via npm audit fix.
- Scanner
- osv-scanner 2.4.0
- Rule
- GHSA-3jxr-9vmj-r5cp:pkg:33bd75a43666b34e8d957c42
- File role
- production
- Source
- package-lock.json
Dependency advisory GHSA-28wg-ghj8-5hjv:pkg:d681b9f3617b82bd6b835445 applies
Minor caution · medium confidence
A small library for creating random IDs is outdated. The vulnerability might make IDs slightly guessable, but this app doesn't use them for anything sensitive.
Technical evidence
Scanner reason: OSV-Scanner matched advisory GHSA-28wg-ghj8-5hjv:pkg:d681b9f3617b82bd6b835445 to a dependency declared by this repository.
Contextual assessment: nanoid@3.3.12 is a library for generating unique IDs. The advisory (GHSA-28wg-ghj8-5hjv) relates to predictability or collision issues. In this frontend, nanoid is likely used for UI keys or temporary IDs. Even if predictable, the impact is limited to minor information disclosure or state confusion. No attacker control over ID generation is demonstrated.
Impact: low · Exploitability: unlikely
Developer action: Update nanoid to version 3.3.13 or later.
- Scanner
- osv-scanner 2.4.0
- Rule
- GHSA-28wg-ghj8-5hjv:pkg:d681b9f3617b82bd6b835445
- File role
- production
- Source
- package-lock.json
Dependency advisory GHSA-4c8g-83qw-93j6:pkg:a90c096b0a189e0f49499767 applies
Minor caution · medium confidence
A library that handles web addresses has a bug. It's buried deep in the dependencies and not directly used by the app's features.
Technical evidence
Scanner reason: OSV-Scanner matched advisory GHSA-4c8g-83qw-93j6:pkg:a90c096b0a189e0f49499767 to a dependency declared by this repository.
Contextual assessment: fast-uri@3.1.2 is a URI parsing library. The advisory (GHSA-4c8g-83qw-93j6) may cause denial of service or incorrect parsing. In this frontend, fast-uri is a transitive dependency of express or other server components. Without evidence that attacker-controlled URIs are parsed by this vulnerable code path, exposure is not demonstrated.
Impact: low · Exploitability: unlikely
Developer action: Update fast-uri to a patched version.
- Scanner
- osv-scanner 2.4.0
- Rule
- GHSA-4c8g-83qw-93j6:pkg:a90c096b0a189e0f49499767
- File role
- production
- Source
- package-lock.json
Dependency advisory GHSA-4w7w-66w2-5vf9:pkg:cdcea1ddcbe6ed9555aaec70 applies
Minor caution · medium confidence
The build tool used to create the app has a security notice. Since it's only used during development and not when running the app, it's not a concern for users.
Technical evidence
Scanner reason: OSV-Scanner matched advisory GHSA-4w7w-66w2-5vf9:pkg:cdcea1ddcbe6ed9555aaec70 to a dependency declared by this repository.
Contextual assessment: vite@7.2.2 is a build tool listed as a devDependency. The advisory (GHSA-4w7w-66w2-5vf9) likely affects development server or build process. It does not affect production runtime. No attacker can exploit this unless they have local access during development, which is not a realistic threat model for end users.
Impact: low · Exploitability: unlikely
Developer action: Update vite to version 7.2.3 or later.
- Scanner
- osv-scanner 2.4.0
- Rule
- GHSA-4w7w-66w2-5vf9:pkg:cdcea1ddcbe6ed9555aaec70
- File role
- production
- Source
- package-lock.json
Dependency advisory GHSA-mh99-v99m-4gvg:pkg:17a4bca76c8dccd42bb43bfa applies
Minor caution · medium confidence
Another version of the text pattern library has a bug that could slow things down, but it's not reachable by attackers.
Technical evidence
Scanner reason: OSV-Scanner matched advisory GHSA-mh99-v99m-4gvg:pkg:17a4bca76c8dccd42bb43bfa to a dependency declared by this repository.
Contextual assessment: brace-expansion@5.0.7 is a newer version used by some dependency. The advisory (GHSA-mh99-v99m-4gvg) is a regex denial of service. As with the older version, no demonstrated attacker-controlled path in production use.
Impact: low · Exploitability: unlikely
Developer action: Update to a patched version of brace-expansion.
- Scanner
- osv-scanner 2.4.0
- Rule
- GHSA-mh99-v99m-4gvg:pkg:17a4bca76c8dccd42bb43bfa
- File role
- production
- Source
- package-lock.json
Dependency advisory GHSA-jr45-8vmc-qm54:pkg:ef6cbe09bba3516afec0221f applies
Minor caution · medium confidence
The server part of the app uses an outdated networking library. While it could be exploited if someone sends malicious network traffic, the app only listens on your own computer, making it very hard for an attacker to reach.
Technical evidence
Scanner reason: OSV-Scanner matched advisory GHSA-jr45-8vmc-qm54:pkg:ef6cbe09bba3516afec0221f to a dependency declared by this repository.
Contextual assessment: undici@7.28.0 is an HTTP client used by the Node.js server (express is a production dependency). The advisory (GHSA-jr45-8vmc-qm54) could allow HTTP request smuggling or other network-level attacks. However, the server listens only on localhost by default, reducing the attack surface. No evidence that attacker-controlled traffic reaches the vulnerable component in this configuration. Exposure is not demonstrated.
Impact: low · Exploitability: plausible
Developer action: Update undici to a patched version (7.28.1 or later) and review server configuration.
- Scanner
- osv-scanner 2.4.0
- Rule
- GHSA-jr45-8vmc-qm54:pkg:ef6cbe09bba3516afec0221f
- File role
- production
- Source
- package-lock.json
Dependency advisory GHSA-rgw5-rvv9-x895:pkg:c15eeb4b6498ad284f4ce31d applies
Minor caution · medium confidence
Another bug in the same library. Still not reachable by attackers.
Technical evidence
Scanner reason: OSV-Scanner matched advisory GHSA-rgw5-rvv9-x895:pkg:c15eeb4b6498ad284f4ce31d to a dependency declared by this repository.
Contextual assessment: Another advisory for brace-expansion@5.0.7 (GHSA-rgw5-rvv9-x895). Same package, different vulnerability. No demonstrated exposure.
Impact: low · Exploitability: unlikely
Developer action: Update brace-expansion to a version that fixes both advisories.
- Scanner
- osv-scanner 2.4.0
- Rule
- GHSA-rgw5-rvv9-x895:pkg:c15eeb4b6498ad284f4ce31d
- File role
- production
- Source
- package-lock.json
Deterministic technical evidence (5)
-
JavaScript analysis reported javascript.xray.serialize-environment · javascript-analysis webcrack-2.16.0_js-x-ray-16.0.0_signatures-1_literals-1_families-1
This technical signal is not part of the shipped runtime behavior.
Policy reason: javascript-xray-inert-tooling · Execution scope: tooling-only
Source: vite.config.ts:79
-
JavaScript analysis reported javascript.xray.serialize-environment · javascript-analysis webcrack-2.16.0_js-x-ray-16.0.0_signatures-1_literals-1_families-1
This technical signal is not part of the shipped runtime behavior.
Policy reason: javascript-xray-inert-tooling · Execution scope: tooling-only
Source: scripts/build-profile.js:4
-
JavaScript analysis reported javascript.xray.unsafe-command · javascript-analysis webcrack-2.16.0_js-x-ray-16.0.0_signatures-1_literals-1_families-1
This technical signal is not part of the shipped runtime behavior.
Policy reason: javascript-xray-inert-tooling · Execution scope: tooling-only
Source: scripts/build-profile.js:8-12
-
JavaScript analysis reported javascript.xray.shady-link · javascript-analysis webcrack-2.16.0_js-x-ray-16.0.0_signatures-1_literals-1_families-1
This technical signal is not part of the shipped runtime behavior.
Policy reason: javascript-xray-inert-tooling · Execution scope: tooling-only
Source: vite.config.ts:32
-
JavaScript analysis reported javascript.xray.data-exfiltration · javascript-analysis webcrack-2.16.0_js-x-ray-16.0.0_signatures-1_literals-1_families-1
This technical signal is not part of the shipped runtime behavior.
Policy reason: javascript-xray-inert-tooling · Execution scope: tooling-only
Source: vite.config.ts:3
Contextual expected matches (12)
OpenGrep reported tavernkeeper.persistence.startup-modification
Expected behavior · high confidence
The security tool flagged a line of CSS styling as a startup modification, but it's just a style rule for arranging buttons, not any actual code that runs.
Technical evidence
Scanner reason: OpenGrep matched static-analysis rule tavernkeeper.persistence.startup-modification in this repository.
Contextual assessment: The scanner matched a 'startup-modification' rule on CSS class selector .profile-actions at line 473, which is within a scoped style block. This line defines visual layout, not runtime logic. No startup persistence behavior exists.
Impact: none · Exploitability: unlikely
Developer action: none
- Scanner
- opengrep 1.26.0
- Rule
- tavernkeeper.persistence.startup-modification
- File role
- production
- Source
- src/extensions/built-in/model-randomizer/SettingsPanel.vue:473
JavaScript analysis reported javascript.xray.unsafe-command
Expected behavior · high confidence
The launcher runs a git command to check the current version, which is needed for automatic updates. The command is fixed and cannot be altered by an attacker.
Technical evidence
Scanner reason: JavaScript analysis matched static JavaScript security signal javascript.xray.unsafe-command in this repository.
Contextual assessment: The execSync call at line 162 runs 'git rev-parse HEAD' to obtain the current commit hash for cache invalidation. The command argument is a hardcoded string with no user input interpolation. This is legitimate behavior for a launcher that manages git-based project updates.
Impact: none · Exploitability: unlikely
Developer action: none
- Scanner
- javascript-analysis webcrack-2.16.0_js-x-ray-16.0.0_signatures-1_literals-1_families-1
- Rule
- javascript.xray.unsafe-command
- File role
- production
- Source
- launcher.js:162
OpenGrep reported tavernkeeper.persistence.startup-modification
Expected behavior · high confidence
The security tool flagged a line of CSS styling as a startup modification, but it's just a style rule for a profile management section, not any actual code that runs.
Technical evidence
Scanner reason: OpenGrep matched static-analysis rule tavernkeeper.persistence.startup-modification in this repository.
Contextual assessment: The scanner matched a 'startup-modification' rule on CSS class selector .profile-management at line 458, which is within a scoped style block. This line defines visual layout, not runtime logic. No startup persistence behavior occurs.
Impact: none · Exploitability: unlikely
Developer action: none
- Scanner
- opengrep 1.26.0
- Rule
- tavernkeeper.persistence.startup-modification
- File role
- production
- Source
- src/extensions/built-in/model-randomizer/SettingsPanel.vue:458
OpenGrep reported tavernkeeper.persistence.startup-modification
Expected behavior · high confidence
The security tool flagged a line of CSS styling as a startup modification, but it's just a style rule for a content area, not any actual code that runs.
Technical evidence
Scanner reason: OpenGrep matched static-analysis rule tavernkeeper.persistence.startup-modification in this repository.
Contextual assessment: The scanner matched a 'startup-modification' rule on CSS class selector .profile-content at line 479, which is within a scoped style block. This line defines visual layout, not runtime logic. No startup persistence behavior exists.
Impact: none · Exploitability: unlikely
Developer action: none
- Scanner
- opengrep 1.26.0
- Rule
- tavernkeeper.persistence.startup-modification
- File role
- production
- Source
- src/extensions/built-in/model-randomizer/SettingsPanel.vue:479
JavaScript analysis reported javascript.xray.shady-link
Expected behavior · high confidence
The launcher has a list of official website addresses that it uses to download the backend. These are fixed and safe.
Technical evidence
Scanner reason: JavaScript analysis matched static JavaScript security signal javascript.xray.shady-link in this repository.
Contextual assessment: The URLs in REPO_URLS point to the official SillyTavern and NeoTavern GitHub repositories. These are hardcoded, not user-supplied, and are used for cloning the backend and plugin. No dynamic or user-controlled redirection is present.
Impact: none · Exploitability: unlikely
Developer action: none
- Scanner
- javascript-analysis webcrack-2.16.0_js-x-ray-16.0.0_signatures-1_literals-1_families-1
- Rule
- javascript.xray.shady-link
- File role
- production
- Source
- launcher.js:31
JavaScript analysis reported javascript.xray.serialize-environment
Expected behavior · high confidence
The security tool flagged a line that reads an environment variable while building the app. The variable is only the project version number and is used to add a version label to the generated code, which is normal and harmless.
Technical evidence
Scanner reason: JavaScript analysis matched static JavaScript security signal javascript.xray.serialize-environment in this repository.
Contextual assessment: The scanner flagged usage of process.env at line 18 in a Vite build config. This reads the benign npm_package_version environment variable to embed a version comment in generated TypeScript declaration files. No credentials or secrets are accessed or exfiltrated. This is standard build-time metadata injection.
Impact: none · Exploitability: unlikely
Developer action: none
- Scanner
- javascript-analysis webcrack-2.16.0_js-x-ray-16.0.0_signatures-1_literals-1_families-1
- Rule
- javascript.xray.serialize-environment
- File role
- production
- Source
- vite.config.types.ts:18
JavaScript analysis reported javascript.xray.serialize-environment
Expected behavior · high confidence
The launcher reads settings from environment variables, which is a common and expected way to configure programs. No secret information is being sent anywhere.
Technical evidence
Scanner reason: JavaScript analysis matched static JavaScript security signal javascript.xray.serialize-environment in this repository.
Contextual assessment: The code reads environment variables (NEO_*) and writes them into the configuration object, which is later saved to disk. This is an intentional override mechanism documented in the project's README. There is no evidence of exfiltration or unintended credential exposure; the config is stored locally.
Impact: none · Exploitability: unlikely
Developer action: none
- Scanner
- javascript-analysis webcrack-2.16.0_js-x-ray-16.0.0_signatures-1_literals-1_families-1
- Rule
- javascript.xray.serialize-environment
- File role
- production
- Source
- launcher.js:110
Gitleaks reported generic-api-key
Expected behavior · high confidence
A security scanner mistakenly thought a line of code was a leaked password. It's actually just telling the app where to store an API key, not exposing the key itself. This is normal.
Technical evidence
Scanner reason: Gitleaks matched secret-detection rule generic-api-key in this repository.
Contextual assessment: Gitleaks flagged line 169 which contains `{ widget: 'key-manager', label: 'apiConnections.ai21Key', secretKey: SECRET_KEYS.AI21 }`. This is a UI configuration object that references a constant name for managing AI21 API keys. It does not contain an actual credential. The pattern 'secretKey' with a constant value triggered the scanner. This is expected behavior for a SillyTavern frontend that handles API key management.
Impact: none · Exploitability: unlikely
Developer action: none
- Scanner
- gitleaks 8.30.1
- Rule
- generic-api-key
- File role
- production
- Source
- src/api-connection-definition.ts:169
OpenGrep reported tavernkeeper.persistence.startup-modification
Expected behavior · high confidence
The security tool flagged a line of CSS styling as a startup modification, but it's just a style rule for arranging profile rows, not any actual code that runs.
Technical evidence
Scanner reason: OpenGrep matched static-analysis rule tavernkeeper.persistence.startup-modification in this repository.
Contextual assessment: The scanner matched a 'startup-modification' rule on CSS class selector .profile-row at line 304, which is within a scoped style block. This line defines visual layout for profile rows, not runtime logic. No startup persistence behavior exists.
Impact: none · Exploitability: unlikely
Developer action: none
- Scanner
- opengrep 1.26.0
- Rule
- tavernkeeper.persistence.startup-modification
- File role
- production
- Source
- src/extensions/built-in/mythic-agents/components/NpcTab.vue:304
Gitleaks reported generic-api-key
Expected behavior · high confidence
The scanner thought a line of code might contain a password, but it's just a placeholder pointing to where the real password will be stored. No actual password is exposed.
Technical evidence
Scanner reason: Gitleaks matched secret-detection rule generic-api-key in this repository.
Contextual assessment: Gitleaks flagged a reference to the constant SECRET_KEYS.AI21 in a UI configuration object. This is a symbolic key reference, not an actual credential. The code defines API key input fields using a key-manager widget and a secretKey constant, which is legitimate and expected behavior for an AI frontend that manages multiple provider keys.
Impact: none · Exploitability: unlikely
Developer action: none
- Scanner
- gitleaks 8.30.1
- Rule
- generic-api-key
- File role
- production
- Source
- src/api-connection-definition.ts:169
OpenGrep reported tavernkeeper.persistence.startup-modification
Expected behavior · high confidence
A security scanner thought a CSS style was suspicious. It's just styling for a popup window. The app saves your settings normally, like any other app.
Technical evidence
Scanner reason: OpenGrep matched static-analysis rule tavernkeeper.persistence.startup-modification in this repository.
Contextual assessment: OpenGrep flagged line 109 in MemoryPopup.vue with a rule 'tavernkeeper.persistence.startup-modification'. The flagged line is `.profile-section {` in a CSS block. The component uses standard Vue lifecycle (onMounted) to load settings and watch to save user preferences. This is normal UI persistence, not malicious startup modification. The scanner rule appears to have a false positive on this line.
Impact: none · Exploitability: unlikely
Developer action: none
- Scanner
- opengrep 1.26.0
- Rule
- tavernkeeper.persistence.startup-modification
- File role
- production
- Source
- src/extensions/built-in/chat-memory/MemoryPopup.vue:109
OpenGrep reported tavernkeeper.persistence.startup-modification
Expected behavior · high confidence
The security tool flagged a line of CSS styling as a startup modification, but it's just a style rule for control buttons, not any actual code that runs.
Technical evidence
Scanner reason: OpenGrep matched static-analysis rule tavernkeeper.persistence.startup-modification in this repository.
Contextual assessment: The scanner matched a 'startup-modification' rule on CSS class selector .profile-controls at line 464, which is within a scoped style block. This line defines visual layout, not runtime logic. No startup persistence behavior occurs.
Impact: none · Exploitability: unlikely
Developer action: none
- Scanner
- opengrep 1.26.0
- Rule
- tavernkeeper.persistence.startup-modification
- File role
- production
- Source
- src/extensions/built-in/model-randomizer/SettingsPanel.vue:464