TavernKeeper Scan Report

mechamarmot/SillyTavern-LocalImage

Commit b08838e Reviewed

No material or immediate-danger concern was identified in this review.

This advisory report describes what the named tools and review process found at one exact commit. Unknown or unobserved behavior may still exist.

0 immediate danger 0 material 30 low

What this review found

No material or immediate-danger item was identified.

Minor cautions

Dependency advisory GHSA-v6h2-p8h4-qcjw applies

Minor caution · medium confidence

A scanner found a minor known security issue in one of the tools used to build this extension. Since it is likely in a build-only tool and not in the final extension users run, the practical risk is low.

Technical evidence

Scanner reason: OSV-Scanner matched advisory GHSA-v6h2-p8h4-qcjw to a dependency declared by this repository.

Contextual assessment: OSV-Scanner matched a low-severity advisory against a declared dependency in the lockfile. The project's production dependencies are limited to React and React-DOM; the remaining declared packages are build-time dev dependencies (Babel, Webpack, ESLint) that are not shipped in the dist bundle. A low-severity advisory in this dependency tree is unlikely to affect end users of the built extension.

Impact: low · Exploitability: unlikely

Developer action: Run npm audit and update affected dependencies to patched versions during the next build cycle.

Scanner
osv-scanner 2.4.0
Rule
GHSA-v6h2-p8h4-qcjw
File role
production
Source
package-lock.json

Dependency advisory GHSA-4x5r-pxfx-6jf8 applies

Minor caution · medium confidence

A scanner found a minor known security issue in a build tool. Because the tool is only used during development and is not included in the final product, the risk to users is low.

Technical evidence

Scanner reason: OSV-Scanner matched advisory GHSA-4x5r-pxfx-6jf8 to a dependency declared by this repository.

Contextual assessment: OSV-Scanner matched a low-severity advisory against a declared dependency. The lockfile shows the root package has only React and React-DOM as production dependencies; all other packages are devDependencies used during the build step. A low-severity advisory in build tooling does not propagate to the shipped dist output.

Impact: low · Exploitability: unlikely

Developer action: Run npm audit and update affected dependencies to patched versions during the next build cycle.

Scanner
osv-scanner 2.4.0
Rule
GHSA-4x5r-pxfx-6jf8
File role
production
Source
package-lock.json

Dependency advisory GHSA-fv7c-fp4j-7gwp applies

Minor caution · medium confidence

A scanner flagged a serious known issue in a dependency, but this project only ships a small React-based browser extension. The flagged package is most likely a build tool that does not end up in the final product users run.

Technical evidence

Scanner reason: OSV-Scanner matched advisory GHSA-fv7c-fp4j-7gwp to a dependency declared by this repository.

Contextual assessment: OSV-Scanner matched a high-severity advisory, but the project's dependency structure limits practical impact. The root package declares only React and React-DOM as production dependencies. The extensive Babel, Webpack, and ESLint dependency trees are devDependencies that are not included in the built extension output. Without confirmation that the flagged package is a runtime dependency, the advisory most likely affects build-time tooling only.

Impact: low · Exploitability: unlikely

Developer action: Run npm audit to identify the specific package, confirm whether it is a dev or production dependency, and update to a patched version. If it is a production dependency, prioritize the update.

Scanner
osv-scanner 2.4.0
Rule
GHSA-fv7c-fp4j-7gwp
File role
production
Source
package-lock.json

Dependency advisory GHSA-qj8w-gfj5-8c6v applies

Minor caution · medium confidence

A scanner found a medium-level known issue in a build tool. Since the tool is only used during development and is not part of the final extension, the risk to users is low.

Technical evidence

Scanner reason: OSV-Scanner matched advisory GHSA-qj8w-gfj5-8c6v to a dependency declared by this repository.

Contextual assessment: OSV-Scanner matched a medium-severity advisory against a declared dependency. The project ships only React and React-DOM as production dependencies; all other packages in the lockfile are devDependencies for the build pipeline. A medium-severity advisory in build tooling does not affect the runtime extension.

Impact: low · Exploitability: unlikely

Developer action: Run npm audit and update affected dependencies to patched versions during the next build cycle.

Scanner
osv-scanner 2.4.0
Rule
GHSA-qj8w-gfj5-8c6v
File role
production
Source
package-lock.json

Dependency advisory GHSA-5c6j-r48x-rmvq applies

Minor caution · medium confidence

A scanner flagged a serious known issue, but it is most likely in a build tool that does not get included in the final extension. The risk to users is low.

Technical evidence

Scanner reason: OSV-Scanner matched advisory GHSA-5c6j-r48x-rmvq to a dependency declared by this repository.

Contextual assessment: OSV-Scanner matched a high-severity advisory. The project's production dependency surface is limited to React and React-DOM, with all other packages being devDependencies for Babel, Webpack, and ESLint. The flagged advisory is most likely in the build toolchain, which does not ship in the dist output. Without confirmation that the flagged package is a runtime dependency, the practical risk to end users is low.

Impact: low · Exploitability: unlikely

Developer action: Run npm audit to identify the specific package, confirm whether it is a dev or production dependency, and update to a patched version. If it is a production dependency, prioritize the update.

Scanner
osv-scanner 2.4.0
Rule
GHSA-5c6j-r48x-rmvq
File role
production
Source
package-lock.json

Dependency advisory GHSA-xxjr-mmjv-4gpg applies

Minor caution · medium confidence

A scanner found a medium-level known issue in a build tool. Because the tool is only used during development and is not included in the final product, the risk to users is low.

Technical evidence

Scanner reason: OSV-Scanner matched advisory GHSA-xxjr-mmjv-4gpg to a dependency declared by this repository.

Contextual assessment: OSV-Scanner matched a medium-severity advisory against a declared dependency. The lockfile shows the root package has only React and React-DOM as production dependencies; all other packages are devDependencies used during the build step. A medium-severity advisory in build tooling does not propagate to the shipped dist output.

Impact: low · Exploitability: unlikely

Developer action: Run npm audit and update affected dependencies to patched versions during the next build cycle.

Scanner
osv-scanner 2.4.0
Rule
GHSA-xxjr-mmjv-4gpg
File role
production
Source
package-lock.json

Dependency advisory GHSA-v2hh-gcrm-f6hx applies

Minor caution · medium confidence

A scanner flagged a serious known issue, but it is most likely in a build tool that does not get included in the final extension. The risk to users is low.

Technical evidence

Scanner reason: OSV-Scanner matched advisory GHSA-v2hh-gcrm-f6hx to a dependency declared by this repository.

Contextual assessment: OSV-Scanner matched a high-severity advisory. The project ships only React and React-DOM as production dependencies; the remaining packages are devDependencies for the Babel, Webpack, and ESLint build pipeline. The flagged advisory is most likely in build-time tooling that does not ship in the dist output. Without confirmation that the flagged package is a runtime dependency, the practical risk to end users is low.

Impact: low · Exploitability: unlikely

Developer action: Run npm audit to identify the specific package, confirm whether it is a dev or production dependency, and update to a patched version. If it is a production dependency, prioritize the update.

Scanner
osv-scanner 2.4.0
Rule
GHSA-v2hh-gcrm-f6hx
File role
production
Source
package-lock.json

Dependency advisory GHSA-f23m-r3pf-42rh applies

Minor caution · medium confidence

A scanner found a medium-level known issue in a build tool. Since the tool is only used during development and is not part of the final extension, the risk to users is low.

Technical evidence

Scanner reason: OSV-Scanner matched advisory GHSA-f23m-r3pf-42rh to a dependency declared by this repository.

Contextual assessment: OSV-Scanner matched a medium-severity advisory against a declared dependency. The project's production dependencies are limited to React and React-DOM; all other packages are devDependencies for the build pipeline. A medium-severity advisory in build tooling does not affect the runtime extension.

Impact: low · Exploitability: unlikely

Developer action: Run npm audit and update affected dependencies to patched versions during the next build cycle.

Scanner
osv-scanner 2.4.0
Rule
GHSA-f23m-r3pf-42rh
File role
production
Source
package-lock.json

Dependency advisory GHSA-25h7-pfq9-p65f applies

Minor caution · medium confidence

A scanner found that one of the tools used to build this extension has a known security flaw. Because this tool is only used during development and is not included in the final extension that users run, the practical risk to users is low.

Technical evidence

Scanner reason: OSV-Scanner matched advisory GHSA-25h7-pfq9-p65f to a dependency declared by this repository.

Contextual assessment: OSV-Scanner matched a known high-severity advisory against a declared dependency in the package-lock.json. The project's runtime dependencies are limited to React and React-DOM; the remaining dependency tree consists of build-time devDependencies (Babel, webpack, ESLint, terser). Vulnerabilities in build-tool transitive dependencies do not ship in the compiled extension output and are not exercised at runtime by end users. No evidence of malicious code, credential access, or runtime data flow was found.

Impact: low · Exploitability: unlikely

Developer action: Update affected devDependencies to patched versions by running npm audit fix or manually bumping the vulnerable package in package-lock.json.

Scanner
osv-scanner 2.4.0
Rule
GHSA-25h7-pfq9-p65f
File role
production
Source
package-lock.json

Dependency advisory GHSA-2g4f-4pwh-qvx6 applies

Minor caution · medium confidence

A scanner found a medium-severity flaw in one of the development tools listed in this project. Since the tool is only used to build the extension and is not part of what users actually run, the risk to users is low.

Technical evidence

Scanner reason: OSV-Scanner matched advisory GHSA-2g4f-4pwh-qvx6 to a dependency declared by this repository.

Contextual assessment: OSV-Scanner matched a known medium-severity advisory against a declared dependency in the package-lock.json. The project's dependency tree is dominated by build-time devDependencies; the compiled extension output that runs in SillyTavern does not include these packages. No runtime data flow, credential handling, or network exfiltration is associated with this dependency finding.

Impact: low · Exploitability: unlikely

Developer action: Update the affected dependency to a patched version during the next build cycle.

Scanner
osv-scanner 2.4.0
Rule
GHSA-2g4f-4pwh-qvx6
File role
production
Source
package-lock.json

Dependency advisory GHSA-v39h-62p7-jpjc applies

Minor caution · medium confidence

A scanner found a known security issue in a build tool used by this project. The tool is not included in the final extension, so the risk to people using the extension is low.

Technical evidence

Scanner reason: OSV-Scanner matched advisory GHSA-v39h-62p7-jpjc to a dependency declared by this repository.

Contextual assessment: OSV-Scanner matched a known high-severity advisory against a declared dependency in the package-lock.json. The project ships a compiled browser extension; the vulnerable package is part of the build toolchain rather than the runtime bundle. No evidence of runtime exploitation path, credential access, or malicious behavior was found in the supplied evidence.

Impact: low · Exploitability: unlikely

Developer action: Update the affected devDependency to a patched version.

Scanner
osv-scanner 2.4.0
Rule
GHSA-v39h-62p7-jpjc
File role
production
Source
package-lock.json

Dependency advisory GHSA-h67p-54hq-rp68 applies

Minor caution · medium confidence

A scanner found a medium-level flaw in a development dependency. Because it is only used during building and not shipped to users, the practical risk is low.

Technical evidence

Scanner reason: OSV-Scanner matched advisory GHSA-h67p-54hq-rp68 to a dependency declared by this repository.

Contextual assessment: OSV-Scanner matched a known medium-severity advisory against a declared dependency in the package-lock.json. The project's runtime surface is limited to React and React-DOM; the advisory targets a package in the build-time dependency tree. No runtime data flow or user-facing security impact was identified.

Impact: low · Exploitability: unlikely

Developer action: Update the affected dependency to a patched version.

Scanner
osv-scanner 2.4.0
Rule
GHSA-h67p-54hq-rp68
File role
production
Source
package-lock.json

Dependency advisory GHSA-q3j6-qgpj-74h6 applies

Minor caution · medium confidence

A scanner found a high-severity flaw in a build tool dependency. Since the tool is not part of the final extension users run, the risk to users is low.

Technical evidence

Scanner reason: OSV-Scanner matched advisory GHSA-q3j6-qgpj-74h6 to a dependency declared by this repository.

Contextual assessment: OSV-Scanner matched a known high-severity advisory against a declared dependency in the package-lock.json. The vulnerable package is part of the development build toolchain (Babel, webpack, ESLint, or terser transitive dependencies). The compiled extension output does not include these packages, and no runtime exploitation path was identified in the supplied evidence.

Impact: low · Exploitability: unlikely

Developer action: Update the affected devDependency to a patched version.

Scanner
osv-scanner 2.4.0
Rule
GHSA-q3j6-qgpj-74h6
File role
production
Source
package-lock.json

Dependency advisory GHSA-23c5-xmqv-rm74 applies

Minor caution · medium confidence

A scanner found a known security issue in a development tool used to build this extension. The tool is not shipped to users, so the practical risk is low.

Technical evidence

Scanner reason: OSV-Scanner matched advisory GHSA-23c5-xmqv-rm74 to a dependency declared by this repository.

Contextual assessment: OSV-Scanner matched a known high-severity advisory against a declared dependency in the package-lock.json. The project's runtime dependencies are React and React-DOM; the advisory is associated with a build-time transitive dependency. No runtime data flow, credential handling, or malicious behavior was found.

Impact: low · Exploitability: unlikely

Developer action: Update the affected devDependency to a patched version.

Scanner
osv-scanner 2.4.0
Rule
GHSA-23c5-xmqv-rm74
File role
production
Source
package-lock.json

Dependency advisory GHSA-3jxr-9vmj-r5cp applies

Minor caution · medium confidence

A scanner found a high-severity flaw in a build-time dependency. Because it is not included in the extension that users run, the risk to users is low.

Technical evidence

Scanner reason: OSV-Scanner matched advisory GHSA-3jxr-9vmj-r5cp to a dependency declared by this repository.

Contextual assessment: OSV-Scanner matched a known high-severity advisory against a declared dependency in the package-lock.json. The vulnerable package belongs to the build toolchain rather than the runtime bundle. The extension's stated purpose is local image handling in SillyTavern, and no runtime exploitation path or malicious data flow was identified.

Impact: low · Exploitability: unlikely

Developer action: Update the affected devDependency to a patched version.

Scanner
osv-scanner 2.4.0
Rule
GHSA-3jxr-9vmj-r5cp
File role
production
Source
package-lock.json

Dependency advisory GHSA-7p8r-x3mc-p8w7 applies

Minor caution · medium confidence

A scanner found a known security issue in a development tool dependency. Since the tool is only used during building and is not shipped to users, the practical risk is low.

Technical evidence

Scanner reason: OSV-Scanner matched advisory GHSA-7p8r-x3mc-p8w7 to a dependency declared by this repository.

Contextual assessment: OSV-Scanner matched a known high-severity advisory against a declared dependency in the package-lock.json. The project's runtime surface is limited to React and React-DOM; the advisory targets a package in the build-time dependency tree. No runtime data flow, credential access, or malicious behavior was identified in the supplied evidence.

Impact: low · Exploitability: unlikely

Developer action: Update the affected devDependency to a patched version.

Scanner
osv-scanner 2.4.0
Rule
GHSA-7p8r-x3mc-p8w7
File role
production
Source
package-lock.json

Dependency advisory GHSA-7r86-cg39-jmmj applies

Minor caution · medium confidence

A security scanner found that one of the project's build-tool dependencies has a known vulnerability. Since these tools are only used during development and are not included in the final extension that users install, the risk to end users is low.

Technical evidence

Scanner reason: OSV-Scanner matched advisory GHSA-7r86-cg39-jmmj to a dependency declared by this repository.

Contextual assessment: OSV-Scanner matched a known advisory (GHSA-7r86-cg39-jmmj) against a declared dependency in package-lock.json. The project's production dependencies are limited to react and react-dom at ^18.2.0; the remaining dependencies are dev-only build tools (babel, webpack, terser, eslint). Vulnerable dependencies in this lockfile most likely reside in the dev toolchain, which does not ship to end users in the compiled dist/ output. No malicious code flow, exfiltration, or concealed execution is present in the supplied evidence.

Impact: low · Exploitability: unlikely

Developer action: Run npm audit and update affected dev dependencies to patched versions.

Scanner
osv-scanner 2.4.0
Rule
GHSA-7r86-cg39-jmmj
File role
production
Source
package-lock.json

Dependency advisory GHSA-rf6f-7fwh-wjgh applies

Minor caution · medium confidence

A known vulnerability was found in one of the project's development dependencies. These tools are used only to build the extension and are not shipped to users, so the practical risk is low.

Technical evidence

Scanner reason: OSV-Scanner matched advisory GHSA-rf6f-7fwh-wjgh to a dependency declared by this repository.

Contextual assessment: OSV-Scanner matched advisory GHSA-rf6f-7fwh-wjgh against a dependency in the lockfile. The project declares only react and react-dom as production dependencies; all other packages are devDependencies used for the webpack/babel build pipeline. The compiled extension output in dist/ would not include these build tools. No evidence of malicious data flow or credential handling is present.

Impact: low · Exploitability: unlikely

Developer action: Update the affected dependency to a patched version via npm audit fix or manual version bump.

Scanner
osv-scanner 2.4.0
Rule
GHSA-rf6f-7fwh-wjgh
File role
production
Source
package-lock.json

Dependency advisory GHSA-8fgc-7cc6-rx7x applies

Minor caution · medium confidence

A minor known vulnerability was found in a development dependency. Because it is low severity and only used during building, the risk is minimal.

Technical evidence

Scanner reason: OSV-Scanner matched advisory GHSA-8fgc-7cc6-rx7x to a dependency declared by this repository.

Contextual assessment: OSV-Scanner matched a low-severity advisory (GHSA-8fgc-7cc6-rx7x) against a dependency in package-lock.json. Given the project's dependency profile—react and react-dom in production, build tools in dev—the affected package is most likely a transitive dev dependency. Low-severity advisories in build tooling pose minimal risk to the shipped extension.

Impact: low · Exploitability: unlikely

Developer action: Update the affected dependency when convenient.

Scanner
osv-scanner 2.4.0
Rule
GHSA-8fgc-7cc6-rx7x
File role
production
Source
package-lock.json

Dependency advisory GHSA-r5fr-rjxr-66jc applies

Minor caution · medium confidence

A known vulnerability was found in a build-tool dependency. Since these tools are not included in the final extension, the risk to users is low.

Technical evidence

Scanner reason: OSV-Scanner matched advisory GHSA-r5fr-rjxr-66jc to a dependency declared by this repository.

Contextual assessment: OSV-Scanner matched advisory GHSA-r5fr-rjxr-66jc against a dependency in the lockfile. The project's production dependencies are react and react-dom at ^18.2.0, which are unlikely to carry this advisory. The affected package is most likely a transitive dependency of the babel, webpack, terser, or eslint dev toolchain. Dev dependencies are not included in the compiled dist/ output that end users install.

Impact: low · Exploitability: unlikely

Developer action: Update the affected dependency to a patched version.

Scanner
osv-scanner 2.4.0
Rule
GHSA-r5fr-rjxr-66jc
File role
production
Source
package-lock.json

Dependency advisory GHSA-3v7f-55p6-f55p applies

Minor caution · medium confidence

A medium-severity vulnerability was found in a development dependency. Because it is only used during the build process and not shipped to users, the practical risk is low.

Technical evidence

Scanner reason: OSV-Scanner matched advisory GHSA-3v7f-55p6-f55p to a dependency declared by this repository.

Contextual assessment: OSV-Scanner matched a medium-severity advisory (GHSA-3v7f-55p6-f55p) against a dependency in package-lock.json. The project's only production dependencies are react and react-dom; all other declared packages are devDependencies for the build pipeline. The affected package is most likely a transitive dev dependency that does not ship in the compiled extension.

Impact: low · Exploitability: unlikely

Developer action: Update the affected dependency to a patched version.

Scanner
osv-scanner 2.4.0
Rule
GHSA-3v7f-55p6-f55p
File role
production
Source
package-lock.json

Dependency advisory GHSA-4c8g-83qw-93j6 applies

Minor caution · medium confidence

A known vulnerability was found in a build-tool dependency. These tools are not included in the extension that users install, so the risk is low.

Technical evidence

Scanner reason: OSV-Scanner matched advisory GHSA-4c8g-83qw-93j6 to a dependency declared by this repository.

Contextual assessment: OSV-Scanner matched advisory GHSA-4c8g-83qw-93j6 against a dependency in the lockfile. The project declares react and react-dom as its only production dependencies; the remaining packages are devDependencies for babel, webpack, terser, and eslint. The affected package is most likely part of the build toolchain and would not be included in the dist/ output installed by end users. No malicious code or data flow is evident.

Impact: low · Exploitability: unlikely

Developer action: Update the affected dependency to a patched version.

Scanner
osv-scanner 2.4.0
Rule
GHSA-4c8g-83qw-93j6
File role
production
Source
package-lock.json

Dependency advisory GHSA-f886-m6hf-6m8v applies

Minor caution · medium confidence

A medium-severity vulnerability was found in a development dependency. Since it is only used during building and not shipped to users, the risk is low.

Technical evidence

Scanner reason: OSV-Scanner matched advisory GHSA-f886-m6hf-6m8v to a dependency declared by this repository.

Contextual assessment: OSV-Scanner matched a medium-severity advisory (GHSA-f886-m6hf-6m8v) against a dependency in package-lock.json. The project's production dependencies are limited to react and react-dom at ^18.2.0. The affected package is most likely a transitive dev dependency in the build toolchain, which does not ship in the compiled extension output.

Impact: low · Exploitability: unlikely

Developer action: Update the affected dependency to a patched version.

Scanner
osv-scanner 2.4.0
Rule
GHSA-f886-m6hf-6m8v
File role
production
Source
package-lock.json

Dependency advisory GHSA-52cp-r559-cp3m applies

Minor caution · medium confidence

A known vulnerability was found in a build-tool dependency. These tools are not part of the extension that users install, so the risk is low.

Technical evidence

Scanner reason: OSV-Scanner matched advisory GHSA-52cp-r559-cp3m to a dependency declared by this repository.

Contextual assessment: OSV-Scanner matched advisory GHSA-52cp-r559-cp3m against a dependency in the lockfile. The project's only production dependencies are react and react-dom at ^18.2.0. All other packages are devDependencies for the babel, webpack, terser, and eslint build pipeline. The affected package is most likely a transitive dev dependency that is not included in the compiled dist/ output. No malicious behavior is evident in the supplied evidence.

Impact: low · Exploitability: unlikely

Developer action: Update the affected dependency to a patched version.

Scanner
osv-scanner 2.4.0
Rule
GHSA-52cp-r559-cp3m
File role
production
Source
package-lock.json

Dependency advisory GHSA-3ppc-4f35-3m26 applies

Minor caution · medium confidence

A security scanner found a known vulnerability in one of the tools used to build this extension. Since the extension is compiled before distribution, the vulnerable tool likely does not run on the user's machine. The developer should update their build tools to fix it.

Technical evidence

Scanner reason: OSV-Scanner matched advisory GHSA-3ppc-4f35-3m26 to a dependency declared by this repository.

Contextual assessment: OSV-Scanner matched a high-severity advisory against a dependency declared in the lockfile. The project's dependency tree consists of production dependencies (react, react-dom) and build-time dev dependencies (babel, webpack, eslint, terser). The affected package is most likely a transitive dependency of the build toolchain rather than runtime code shipped to end users. The extension is compiled to a dist bundle, so dev dependencies do not execute in the end user's SillyTavern environment. The vulnerability should be remediated by updating dependencies but does not indicate malicious behavior.

Impact: low · Exploitability: unlikely

Developer action: Run npm audit and update affected dependencies to patched versions. Rebuild and verify the extension still functions correctly.

Scanner
osv-scanner 2.4.0
Rule
GHSA-3ppc-4f35-3m26
File role
production
Source
package-lock.json

Dependency advisory GHSA-mh99-v99m-4gvg applies

Minor caution · medium confidence

A security scanner found a known vulnerability in one of the tools used to build this extension. Since the extension is compiled before distribution, the vulnerable tool likely does not run on the user's machine. The developer should update their build tools to fix it.

Technical evidence

Scanner reason: OSV-Scanner matched advisory GHSA-mh99-v99m-4gvg to a dependency declared by this repository.

Contextual assessment: OSV-Scanner matched a high-severity advisory against a dependency in the lockfile. Given the project's dependency structure, the affected package is most likely a transitive dependency of the webpack/babel/eslint build toolchain. These dev dependencies are used at build time by the developer and are not shipped to end users in the compiled dist output. The advisory should be addressed but does not represent a runtime threat to SillyTavern users.

Impact: low · Exploitability: unlikely

Developer action: Run npm audit and update affected dependencies to patched versions. Rebuild and verify the extension still functions correctly.

Scanner
osv-scanner 2.4.0
Rule
GHSA-mh99-v99m-4gvg
File role
production
Source
package-lock.json

Dependency advisory GHSA-c2c7-rcm5-vvqj applies

Minor caution · medium confidence

A security scanner found a known vulnerability in one of the tools used to build this extension. Since the extension is compiled before distribution, the vulnerable tool likely does not run on the user's machine. The developer should update their build tools to fix it.

Technical evidence

Scanner reason: OSV-Scanner matched advisory GHSA-c2c7-rcm5-vvqj to a dependency declared by this repository.

Contextual assessment: OSV-Scanner matched a high-severity advisory against a dependency in the lockfile. The project's production dependencies are limited to react and react-dom, with the remaining dependencies being build-time dev tooling. The affected package is most likely a transitive dependency of the build toolchain that does not ship in the compiled extension output. Remediation is recommended but this does not indicate malicious intent or a direct runtime risk to users.

Impact: low · Exploitability: unlikely

Developer action: Run npm audit and update affected dependencies to patched versions. Rebuild and verify the extension still functions correctly.

Scanner
osv-scanner 2.4.0
Rule
GHSA-c2c7-rcm5-vvqj
File role
production
Source
package-lock.json

Dependency advisory GHSA-48c2-rrv3-qjmp applies

Minor caution · medium confidence

A security scanner found a medium-level vulnerability in one of the tools used to build this extension. Since the extension is compiled before distribution, the vulnerable tool likely does not run on the user's machine. The developer should update their build tools to fix it.

Technical evidence

Scanner reason: OSV-Scanner matched advisory GHSA-48c2-rrv3-qjmp to a dependency declared by this repository.

Contextual assessment: OSV-Scanner matched a medium-severity advisory against a dependency in the lockfile. Based on the project's dependency structure, the affected package is most likely part of the build toolchain (babel, webpack, eslint, or their transitive dependencies). These are dev dependencies used at build time and are not included in the compiled dist output distributed to SillyTavern users. The vulnerability should be remediated but poses minimal risk to end users.

Impact: low · Exploitability: unlikely

Developer action: Run npm audit and update affected dependencies to patched versions. Rebuild and verify the extension still functions correctly.

Scanner
osv-scanner 2.4.0
Rule
GHSA-48c2-rrv3-qjmp
File role
production
Source
package-lock.json

Dependency advisory GHSA-38r7-794h-5758 applies

Minor caution · medium confidence

A security scanner found a low-level vulnerability in one of the tools used to build this extension. This is a minor issue that the developer should fix by updating their tools, but it is unlikely to affect users of the extension.

Technical evidence

Scanner reason: OSV-Scanner matched advisory GHSA-38r7-794h-5758 to a dependency declared by this repository.

Contextual assessment: OSV-Scanner matched a low-severity advisory against a dependency in the lockfile. The project's dependency tree is dominated by build-time dev tooling, and the affected package is most likely a transitive dependency of that toolchain. Low-severity advisories in build dependencies for a client-side compiled extension represent minimal risk to end users. Remediation is still good hygiene.

Impact: low · Exploitability: unlikely

Developer action: Run npm audit and update affected dependencies to patched versions. Rebuild and verify the extension still functions correctly.

Scanner
osv-scanner 2.4.0
Rule
GHSA-38r7-794h-5758
File role
production
Source
package-lock.json

Dependency advisory GHSA-rgw5-rvv9-x895 applies

Minor caution · medium confidence

A security scanner found a known vulnerability in one of the tools used to build this extension. Since the extension is compiled before distribution, the vulnerable tool likely does not run on the user's machine. The developer should update their build tools to fix it.

Technical evidence

Scanner reason: OSV-Scanner matched advisory GHSA-rgw5-rvv9-x895 to a dependency declared by this repository.

Contextual assessment: OSV-Scanner matched a high-severity advisory against a dependency in the lockfile. The project's production dependencies are react and react-dom, with all other declared dependencies being build-time dev tooling. The affected package is most likely a transitive dependency of the webpack, babel, or eslint toolchain. Since the extension is compiled to a dist bundle before distribution, dev dependencies do not execute in the end user's SillyTavern environment. The advisory should be remediated by updating dependencies but does not indicate malicious behavior or a direct runtime threat to users.

Impact: low · Exploitability: unlikely

Developer action: Run npm audit and update affected dependencies to patched versions. Rebuild and verify the extension still functions correctly.

Scanner
osv-scanner 2.4.0
Rule
GHSA-rgw5-rvv9-x895
File role
production
Source
package-lock.json
Expected scanner matches (0)

None.

Coverage and limitations

Tools

Limitations

Technical scan identity