What this review found
No material or immediate-danger item was identified.
Minor cautions
Dependency advisory GHSA-v6h2-p8h4-qcjw applies
Minor caution · medium confidence
A scanner found a minor known security issue in one of the tools used to build this extension. Since it is likely in a build-only tool and not in the final extension users run, the practical risk is low.
Technical evidence
Scanner reason: OSV-Scanner matched advisory GHSA-v6h2-p8h4-qcjw to a dependency declared by this repository.
Contextual assessment: OSV-Scanner matched a low-severity advisory against a declared dependency in the lockfile. The project's production dependencies are limited to React and React-DOM; the remaining declared packages are build-time dev dependencies (Babel, Webpack, ESLint) that are not shipped in the dist bundle. A low-severity advisory in this dependency tree is unlikely to affect end users of the built extension.
Impact: low · Exploitability: unlikely
Developer action: Run npm audit and update affected dependencies to patched versions during the next build cycle.
- Scanner
- osv-scanner 2.4.0
- Rule
- GHSA-v6h2-p8h4-qcjw
- File role
- production
- Source
- package-lock.json
Dependency advisory GHSA-4x5r-pxfx-6jf8 applies
Minor caution · medium confidence
A scanner found a minor known security issue in a build tool. Because the tool is only used during development and is not included in the final product, the risk to users is low.
Technical evidence
Scanner reason: OSV-Scanner matched advisory GHSA-4x5r-pxfx-6jf8 to a dependency declared by this repository.
Contextual assessment: OSV-Scanner matched a low-severity advisory against a declared dependency. The lockfile shows the root package has only React and React-DOM as production dependencies; all other packages are devDependencies used during the build step. A low-severity advisory in build tooling does not propagate to the shipped dist output.
Impact: low · Exploitability: unlikely
Developer action: Run npm audit and update affected dependencies to patched versions during the next build cycle.
- Scanner
- osv-scanner 2.4.0
- Rule
- GHSA-4x5r-pxfx-6jf8
- File role
- production
- Source
- package-lock.json
Dependency advisory GHSA-fv7c-fp4j-7gwp applies
Minor caution · medium confidence
A scanner flagged a serious known issue in a dependency, but this project only ships a small React-based browser extension. The flagged package is most likely a build tool that does not end up in the final product users run.
Technical evidence
Scanner reason: OSV-Scanner matched advisory GHSA-fv7c-fp4j-7gwp to a dependency declared by this repository.
Contextual assessment: OSV-Scanner matched a high-severity advisory, but the project's dependency structure limits practical impact. The root package declares only React and React-DOM as production dependencies. The extensive Babel, Webpack, and ESLint dependency trees are devDependencies that are not included in the built extension output. Without confirmation that the flagged package is a runtime dependency, the advisory most likely affects build-time tooling only.
Impact: low · Exploitability: unlikely
Developer action: Run npm audit to identify the specific package, confirm whether it is a dev or production dependency, and update to a patched version. If it is a production dependency, prioritize the update.
- Scanner
- osv-scanner 2.4.0
- Rule
- GHSA-fv7c-fp4j-7gwp
- File role
- production
- Source
- package-lock.json
Dependency advisory GHSA-qj8w-gfj5-8c6v applies
Minor caution · medium confidence
A scanner found a medium-level known issue in a build tool. Since the tool is only used during development and is not part of the final extension, the risk to users is low.
Technical evidence
Scanner reason: OSV-Scanner matched advisory GHSA-qj8w-gfj5-8c6v to a dependency declared by this repository.
Contextual assessment: OSV-Scanner matched a medium-severity advisory against a declared dependency. The project ships only React and React-DOM as production dependencies; all other packages in the lockfile are devDependencies for the build pipeline. A medium-severity advisory in build tooling does not affect the runtime extension.
Impact: low · Exploitability: unlikely
Developer action: Run npm audit and update affected dependencies to patched versions during the next build cycle.
- Scanner
- osv-scanner 2.4.0
- Rule
- GHSA-qj8w-gfj5-8c6v
- File role
- production
- Source
- package-lock.json
Dependency advisory GHSA-5c6j-r48x-rmvq applies
Minor caution · medium confidence
A scanner flagged a serious known issue, but it is most likely in a build tool that does not get included in the final extension. The risk to users is low.
Technical evidence
Scanner reason: OSV-Scanner matched advisory GHSA-5c6j-r48x-rmvq to a dependency declared by this repository.
Contextual assessment: OSV-Scanner matched a high-severity advisory. The project's production dependency surface is limited to React and React-DOM, with all other packages being devDependencies for Babel, Webpack, and ESLint. The flagged advisory is most likely in the build toolchain, which does not ship in the dist output. Without confirmation that the flagged package is a runtime dependency, the practical risk to end users is low.
Impact: low · Exploitability: unlikely
Developer action: Run npm audit to identify the specific package, confirm whether it is a dev or production dependency, and update to a patched version. If it is a production dependency, prioritize the update.
- Scanner
- osv-scanner 2.4.0
- Rule
- GHSA-5c6j-r48x-rmvq
- File role
- production
- Source
- package-lock.json
Dependency advisory GHSA-xxjr-mmjv-4gpg applies
Minor caution · medium confidence
A scanner found a medium-level known issue in a build tool. Because the tool is only used during development and is not included in the final product, the risk to users is low.
Technical evidence
Scanner reason: OSV-Scanner matched advisory GHSA-xxjr-mmjv-4gpg to a dependency declared by this repository.
Contextual assessment: OSV-Scanner matched a medium-severity advisory against a declared dependency. The lockfile shows the root package has only React and React-DOM as production dependencies; all other packages are devDependencies used during the build step. A medium-severity advisory in build tooling does not propagate to the shipped dist output.
Impact: low · Exploitability: unlikely
Developer action: Run npm audit and update affected dependencies to patched versions during the next build cycle.
- Scanner
- osv-scanner 2.4.0
- Rule
- GHSA-xxjr-mmjv-4gpg
- File role
- production
- Source
- package-lock.json
Dependency advisory GHSA-v2hh-gcrm-f6hx applies
Minor caution · medium confidence
A scanner flagged a serious known issue, but it is most likely in a build tool that does not get included in the final extension. The risk to users is low.
Technical evidence
Scanner reason: OSV-Scanner matched advisory GHSA-v2hh-gcrm-f6hx to a dependency declared by this repository.
Contextual assessment: OSV-Scanner matched a high-severity advisory. The project ships only React and React-DOM as production dependencies; the remaining packages are devDependencies for the Babel, Webpack, and ESLint build pipeline. The flagged advisory is most likely in build-time tooling that does not ship in the dist output. Without confirmation that the flagged package is a runtime dependency, the practical risk to end users is low.
Impact: low · Exploitability: unlikely
Developer action: Run npm audit to identify the specific package, confirm whether it is a dev or production dependency, and update to a patched version. If it is a production dependency, prioritize the update.
- Scanner
- osv-scanner 2.4.0
- Rule
- GHSA-v2hh-gcrm-f6hx
- File role
- production
- Source
- package-lock.json
Dependency advisory GHSA-f23m-r3pf-42rh applies
Minor caution · medium confidence
A scanner found a medium-level known issue in a build tool. Since the tool is only used during development and is not part of the final extension, the risk to users is low.
Technical evidence
Scanner reason: OSV-Scanner matched advisory GHSA-f23m-r3pf-42rh to a dependency declared by this repository.
Contextual assessment: OSV-Scanner matched a medium-severity advisory against a declared dependency. The project's production dependencies are limited to React and React-DOM; all other packages are devDependencies for the build pipeline. A medium-severity advisory in build tooling does not affect the runtime extension.
Impact: low · Exploitability: unlikely
Developer action: Run npm audit and update affected dependencies to patched versions during the next build cycle.
- Scanner
- osv-scanner 2.4.0
- Rule
- GHSA-f23m-r3pf-42rh
- File role
- production
- Source
- package-lock.json
Dependency advisory GHSA-25h7-pfq9-p65f applies
Minor caution · medium confidence
A scanner found that one of the tools used to build this extension has a known security flaw. Because this tool is only used during development and is not included in the final extension that users run, the practical risk to users is low.
Technical evidence
Scanner reason: OSV-Scanner matched advisory GHSA-25h7-pfq9-p65f to a dependency declared by this repository.
Contextual assessment: OSV-Scanner matched a known high-severity advisory against a declared dependency in the package-lock.json. The project's runtime dependencies are limited to React and React-DOM; the remaining dependency tree consists of build-time devDependencies (Babel, webpack, ESLint, terser). Vulnerabilities in build-tool transitive dependencies do not ship in the compiled extension output and are not exercised at runtime by end users. No evidence of malicious code, credential access, or runtime data flow was found.
Impact: low · Exploitability: unlikely
Developer action: Update affected devDependencies to patched versions by running npm audit fix or manually bumping the vulnerable package in package-lock.json.
- Scanner
- osv-scanner 2.4.0
- Rule
- GHSA-25h7-pfq9-p65f
- File role
- production
- Source
- package-lock.json
Dependency advisory GHSA-2g4f-4pwh-qvx6 applies
Minor caution · medium confidence
A scanner found a medium-severity flaw in one of the development tools listed in this project. Since the tool is only used to build the extension and is not part of what users actually run, the risk to users is low.
Technical evidence
Scanner reason: OSV-Scanner matched advisory GHSA-2g4f-4pwh-qvx6 to a dependency declared by this repository.
Contextual assessment: OSV-Scanner matched a known medium-severity advisory against a declared dependency in the package-lock.json. The project's dependency tree is dominated by build-time devDependencies; the compiled extension output that runs in SillyTavern does not include these packages. No runtime data flow, credential handling, or network exfiltration is associated with this dependency finding.
Impact: low · Exploitability: unlikely
Developer action: Update the affected dependency to a patched version during the next build cycle.
- Scanner
- osv-scanner 2.4.0
- Rule
- GHSA-2g4f-4pwh-qvx6
- File role
- production
- Source
- package-lock.json
Dependency advisory GHSA-v39h-62p7-jpjc applies
Minor caution · medium confidence
A scanner found a known security issue in a build tool used by this project. The tool is not included in the final extension, so the risk to people using the extension is low.
Technical evidence
Scanner reason: OSV-Scanner matched advisory GHSA-v39h-62p7-jpjc to a dependency declared by this repository.
Contextual assessment: OSV-Scanner matched a known high-severity advisory against a declared dependency in the package-lock.json. The project ships a compiled browser extension; the vulnerable package is part of the build toolchain rather than the runtime bundle. No evidence of runtime exploitation path, credential access, or malicious behavior was found in the supplied evidence.
Impact: low · Exploitability: unlikely
Developer action: Update the affected devDependency to a patched version.
- Scanner
- osv-scanner 2.4.0
- Rule
- GHSA-v39h-62p7-jpjc
- File role
- production
- Source
- package-lock.json
Dependency advisory GHSA-h67p-54hq-rp68 applies
Minor caution · medium confidence
A scanner found a medium-level flaw in a development dependency. Because it is only used during building and not shipped to users, the practical risk is low.
Technical evidence
Scanner reason: OSV-Scanner matched advisory GHSA-h67p-54hq-rp68 to a dependency declared by this repository.
Contextual assessment: OSV-Scanner matched a known medium-severity advisory against a declared dependency in the package-lock.json. The project's runtime surface is limited to React and React-DOM; the advisory targets a package in the build-time dependency tree. No runtime data flow or user-facing security impact was identified.
Impact: low · Exploitability: unlikely
Developer action: Update the affected dependency to a patched version.
- Scanner
- osv-scanner 2.4.0
- Rule
- GHSA-h67p-54hq-rp68
- File role
- production
- Source
- package-lock.json
Dependency advisory GHSA-q3j6-qgpj-74h6 applies
Minor caution · medium confidence
A scanner found a high-severity flaw in a build tool dependency. Since the tool is not part of the final extension users run, the risk to users is low.
Technical evidence
Scanner reason: OSV-Scanner matched advisory GHSA-q3j6-qgpj-74h6 to a dependency declared by this repository.
Contextual assessment: OSV-Scanner matched a known high-severity advisory against a declared dependency in the package-lock.json. The vulnerable package is part of the development build toolchain (Babel, webpack, ESLint, or terser transitive dependencies). The compiled extension output does not include these packages, and no runtime exploitation path was identified in the supplied evidence.
Impact: low · Exploitability: unlikely
Developer action: Update the affected devDependency to a patched version.
- Scanner
- osv-scanner 2.4.0
- Rule
- GHSA-q3j6-qgpj-74h6
- File role
- production
- Source
- package-lock.json
Dependency advisory GHSA-23c5-xmqv-rm74 applies
Minor caution · medium confidence
A scanner found a known security issue in a development tool used to build this extension. The tool is not shipped to users, so the practical risk is low.
Technical evidence
Scanner reason: OSV-Scanner matched advisory GHSA-23c5-xmqv-rm74 to a dependency declared by this repository.
Contextual assessment: OSV-Scanner matched a known high-severity advisory against a declared dependency in the package-lock.json. The project's runtime dependencies are React and React-DOM; the advisory is associated with a build-time transitive dependency. No runtime data flow, credential handling, or malicious behavior was found.
Impact: low · Exploitability: unlikely
Developer action: Update the affected devDependency to a patched version.
- Scanner
- osv-scanner 2.4.0
- Rule
- GHSA-23c5-xmqv-rm74
- File role
- production
- Source
- package-lock.json
Dependency advisory GHSA-3jxr-9vmj-r5cp applies
Minor caution · medium confidence
A scanner found a high-severity flaw in a build-time dependency. Because it is not included in the extension that users run, the risk to users is low.
Technical evidence
Scanner reason: OSV-Scanner matched advisory GHSA-3jxr-9vmj-r5cp to a dependency declared by this repository.
Contextual assessment: OSV-Scanner matched a known high-severity advisory against a declared dependency in the package-lock.json. The vulnerable package belongs to the build toolchain rather than the runtime bundle. The extension's stated purpose is local image handling in SillyTavern, and no runtime exploitation path or malicious data flow was identified.
Impact: low · Exploitability: unlikely
Developer action: Update the affected devDependency to a patched version.
- Scanner
- osv-scanner 2.4.0
- Rule
- GHSA-3jxr-9vmj-r5cp
- File role
- production
- Source
- package-lock.json
Dependency advisory GHSA-7p8r-x3mc-p8w7 applies
Minor caution · medium confidence
A scanner found a known security issue in a development tool dependency. Since the tool is only used during building and is not shipped to users, the practical risk is low.
Technical evidence
Scanner reason: OSV-Scanner matched advisory GHSA-7p8r-x3mc-p8w7 to a dependency declared by this repository.
Contextual assessment: OSV-Scanner matched a known high-severity advisory against a declared dependency in the package-lock.json. The project's runtime surface is limited to React and React-DOM; the advisory targets a package in the build-time dependency tree. No runtime data flow, credential access, or malicious behavior was identified in the supplied evidence.
Impact: low · Exploitability: unlikely
Developer action: Update the affected devDependency to a patched version.
- Scanner
- osv-scanner 2.4.0
- Rule
- GHSA-7p8r-x3mc-p8w7
- File role
- production
- Source
- package-lock.json
Dependency advisory GHSA-7r86-cg39-jmmj applies
Minor caution · medium confidence
A security scanner found that one of the project's build-tool dependencies has a known vulnerability. Since these tools are only used during development and are not included in the final extension that users install, the risk to end users is low.
Technical evidence
Scanner reason: OSV-Scanner matched advisory GHSA-7r86-cg39-jmmj to a dependency declared by this repository.
Contextual assessment: OSV-Scanner matched a known advisory (GHSA-7r86-cg39-jmmj) against a declared dependency in package-lock.json. The project's production dependencies are limited to react and react-dom at ^18.2.0; the remaining dependencies are dev-only build tools (babel, webpack, terser, eslint). Vulnerable dependencies in this lockfile most likely reside in the dev toolchain, which does not ship to end users in the compiled dist/ output. No malicious code flow, exfiltration, or concealed execution is present in the supplied evidence.
Impact: low · Exploitability: unlikely
Developer action: Run npm audit and update affected dev dependencies to patched versions.
- Scanner
- osv-scanner 2.4.0
- Rule
- GHSA-7r86-cg39-jmmj
- File role
- production
- Source
- package-lock.json
Dependency advisory GHSA-rf6f-7fwh-wjgh applies
Minor caution · medium confidence
A known vulnerability was found in one of the project's development dependencies. These tools are used only to build the extension and are not shipped to users, so the practical risk is low.
Technical evidence
Scanner reason: OSV-Scanner matched advisory GHSA-rf6f-7fwh-wjgh to a dependency declared by this repository.
Contextual assessment: OSV-Scanner matched advisory GHSA-rf6f-7fwh-wjgh against a dependency in the lockfile. The project declares only react and react-dom as production dependencies; all other packages are devDependencies used for the webpack/babel build pipeline. The compiled extension output in dist/ would not include these build tools. No evidence of malicious data flow or credential handling is present.
Impact: low · Exploitability: unlikely
Developer action: Update the affected dependency to a patched version via npm audit fix or manual version bump.
- Scanner
- osv-scanner 2.4.0
- Rule
- GHSA-rf6f-7fwh-wjgh
- File role
- production
- Source
- package-lock.json
Dependency advisory GHSA-8fgc-7cc6-rx7x applies
Minor caution · medium confidence
A minor known vulnerability was found in a development dependency. Because it is low severity and only used during building, the risk is minimal.
Technical evidence
Scanner reason: OSV-Scanner matched advisory GHSA-8fgc-7cc6-rx7x to a dependency declared by this repository.
Contextual assessment: OSV-Scanner matched a low-severity advisory (GHSA-8fgc-7cc6-rx7x) against a dependency in package-lock.json. Given the project's dependency profile—react and react-dom in production, build tools in dev—the affected package is most likely a transitive dev dependency. Low-severity advisories in build tooling pose minimal risk to the shipped extension.
Impact: low · Exploitability: unlikely
Developer action: Update the affected dependency when convenient.
- Scanner
- osv-scanner 2.4.0
- Rule
- GHSA-8fgc-7cc6-rx7x
- File role
- production
- Source
- package-lock.json
Dependency advisory GHSA-r5fr-rjxr-66jc applies
Minor caution · medium confidence
A known vulnerability was found in a build-tool dependency. Since these tools are not included in the final extension, the risk to users is low.
Technical evidence
Scanner reason: OSV-Scanner matched advisory GHSA-r5fr-rjxr-66jc to a dependency declared by this repository.
Contextual assessment: OSV-Scanner matched advisory GHSA-r5fr-rjxr-66jc against a dependency in the lockfile. The project's production dependencies are react and react-dom at ^18.2.0, which are unlikely to carry this advisory. The affected package is most likely a transitive dependency of the babel, webpack, terser, or eslint dev toolchain. Dev dependencies are not included in the compiled dist/ output that end users install.
Impact: low · Exploitability: unlikely
Developer action: Update the affected dependency to a patched version.
- Scanner
- osv-scanner 2.4.0
- Rule
- GHSA-r5fr-rjxr-66jc
- File role
- production
- Source
- package-lock.json
Dependency advisory GHSA-3v7f-55p6-f55p applies
Minor caution · medium confidence
A medium-severity vulnerability was found in a development dependency. Because it is only used during the build process and not shipped to users, the practical risk is low.
Technical evidence
Scanner reason: OSV-Scanner matched advisory GHSA-3v7f-55p6-f55p to a dependency declared by this repository.
Contextual assessment: OSV-Scanner matched a medium-severity advisory (GHSA-3v7f-55p6-f55p) against a dependency in package-lock.json. The project's only production dependencies are react and react-dom; all other declared packages are devDependencies for the build pipeline. The affected package is most likely a transitive dev dependency that does not ship in the compiled extension.
Impact: low · Exploitability: unlikely
Developer action: Update the affected dependency to a patched version.
- Scanner
- osv-scanner 2.4.0
- Rule
- GHSA-3v7f-55p6-f55p
- File role
- production
- Source
- package-lock.json
Dependency advisory GHSA-4c8g-83qw-93j6 applies
Minor caution · medium confidence
A known vulnerability was found in a build-tool dependency. These tools are not included in the extension that users install, so the risk is low.
Technical evidence
Scanner reason: OSV-Scanner matched advisory GHSA-4c8g-83qw-93j6 to a dependency declared by this repository.
Contextual assessment: OSV-Scanner matched advisory GHSA-4c8g-83qw-93j6 against a dependency in the lockfile. The project declares react and react-dom as its only production dependencies; the remaining packages are devDependencies for babel, webpack, terser, and eslint. The affected package is most likely part of the build toolchain and would not be included in the dist/ output installed by end users. No malicious code or data flow is evident.
Impact: low · Exploitability: unlikely
Developer action: Update the affected dependency to a patched version.
- Scanner
- osv-scanner 2.4.0
- Rule
- GHSA-4c8g-83qw-93j6
- File role
- production
- Source
- package-lock.json
Dependency advisory GHSA-f886-m6hf-6m8v applies
Minor caution · medium confidence
A medium-severity vulnerability was found in a development dependency. Since it is only used during building and not shipped to users, the risk is low.
Technical evidence
Scanner reason: OSV-Scanner matched advisory GHSA-f886-m6hf-6m8v to a dependency declared by this repository.
Contextual assessment: OSV-Scanner matched a medium-severity advisory (GHSA-f886-m6hf-6m8v) against a dependency in package-lock.json. The project's production dependencies are limited to react and react-dom at ^18.2.0. The affected package is most likely a transitive dev dependency in the build toolchain, which does not ship in the compiled extension output.
Impact: low · Exploitability: unlikely
Developer action: Update the affected dependency to a patched version.
- Scanner
- osv-scanner 2.4.0
- Rule
- GHSA-f886-m6hf-6m8v
- File role
- production
- Source
- package-lock.json
Dependency advisory GHSA-52cp-r559-cp3m applies
Minor caution · medium confidence
A known vulnerability was found in a build-tool dependency. These tools are not part of the extension that users install, so the risk is low.
Technical evidence
Scanner reason: OSV-Scanner matched advisory GHSA-52cp-r559-cp3m to a dependency declared by this repository.
Contextual assessment: OSV-Scanner matched advisory GHSA-52cp-r559-cp3m against a dependency in the lockfile. The project's only production dependencies are react and react-dom at ^18.2.0. All other packages are devDependencies for the babel, webpack, terser, and eslint build pipeline. The affected package is most likely a transitive dev dependency that is not included in the compiled dist/ output. No malicious behavior is evident in the supplied evidence.
Impact: low · Exploitability: unlikely
Developer action: Update the affected dependency to a patched version.
- Scanner
- osv-scanner 2.4.0
- Rule
- GHSA-52cp-r559-cp3m
- File role
- production
- Source
- package-lock.json
Dependency advisory GHSA-3ppc-4f35-3m26 applies
Minor caution · medium confidence
A security scanner found a known vulnerability in one of the tools used to build this extension. Since the extension is compiled before distribution, the vulnerable tool likely does not run on the user's machine. The developer should update their build tools to fix it.
Technical evidence
Scanner reason: OSV-Scanner matched advisory GHSA-3ppc-4f35-3m26 to a dependency declared by this repository.
Contextual assessment: OSV-Scanner matched a high-severity advisory against a dependency declared in the lockfile. The project's dependency tree consists of production dependencies (react, react-dom) and build-time dev dependencies (babel, webpack, eslint, terser). The affected package is most likely a transitive dependency of the build toolchain rather than runtime code shipped to end users. The extension is compiled to a dist bundle, so dev dependencies do not execute in the end user's SillyTavern environment. The vulnerability should be remediated by updating dependencies but does not indicate malicious behavior.
Impact: low · Exploitability: unlikely
Developer action: Run npm audit and update affected dependencies to patched versions. Rebuild and verify the extension still functions correctly.
- Scanner
- osv-scanner 2.4.0
- Rule
- GHSA-3ppc-4f35-3m26
- File role
- production
- Source
- package-lock.json
Dependency advisory GHSA-mh99-v99m-4gvg applies
Minor caution · medium confidence
A security scanner found a known vulnerability in one of the tools used to build this extension. Since the extension is compiled before distribution, the vulnerable tool likely does not run on the user's machine. The developer should update their build tools to fix it.
Technical evidence
Scanner reason: OSV-Scanner matched advisory GHSA-mh99-v99m-4gvg to a dependency declared by this repository.
Contextual assessment: OSV-Scanner matched a high-severity advisory against a dependency in the lockfile. Given the project's dependency structure, the affected package is most likely a transitive dependency of the webpack/babel/eslint build toolchain. These dev dependencies are used at build time by the developer and are not shipped to end users in the compiled dist output. The advisory should be addressed but does not represent a runtime threat to SillyTavern users.
Impact: low · Exploitability: unlikely
Developer action: Run npm audit and update affected dependencies to patched versions. Rebuild and verify the extension still functions correctly.
- Scanner
- osv-scanner 2.4.0
- Rule
- GHSA-mh99-v99m-4gvg
- File role
- production
- Source
- package-lock.json
Dependency advisory GHSA-c2c7-rcm5-vvqj applies
Minor caution · medium confidence
A security scanner found a known vulnerability in one of the tools used to build this extension. Since the extension is compiled before distribution, the vulnerable tool likely does not run on the user's machine. The developer should update their build tools to fix it.
Technical evidence
Scanner reason: OSV-Scanner matched advisory GHSA-c2c7-rcm5-vvqj to a dependency declared by this repository.
Contextual assessment: OSV-Scanner matched a high-severity advisory against a dependency in the lockfile. The project's production dependencies are limited to react and react-dom, with the remaining dependencies being build-time dev tooling. The affected package is most likely a transitive dependency of the build toolchain that does not ship in the compiled extension output. Remediation is recommended but this does not indicate malicious intent or a direct runtime risk to users.
Impact: low · Exploitability: unlikely
Developer action: Run npm audit and update affected dependencies to patched versions. Rebuild and verify the extension still functions correctly.
- Scanner
- osv-scanner 2.4.0
- Rule
- GHSA-c2c7-rcm5-vvqj
- File role
- production
- Source
- package-lock.json
Dependency advisory GHSA-48c2-rrv3-qjmp applies
Minor caution · medium confidence
A security scanner found a medium-level vulnerability in one of the tools used to build this extension. Since the extension is compiled before distribution, the vulnerable tool likely does not run on the user's machine. The developer should update their build tools to fix it.
Technical evidence
Scanner reason: OSV-Scanner matched advisory GHSA-48c2-rrv3-qjmp to a dependency declared by this repository.
Contextual assessment: OSV-Scanner matched a medium-severity advisory against a dependency in the lockfile. Based on the project's dependency structure, the affected package is most likely part of the build toolchain (babel, webpack, eslint, or their transitive dependencies). These are dev dependencies used at build time and are not included in the compiled dist output distributed to SillyTavern users. The vulnerability should be remediated but poses minimal risk to end users.
Impact: low · Exploitability: unlikely
Developer action: Run npm audit and update affected dependencies to patched versions. Rebuild and verify the extension still functions correctly.
- Scanner
- osv-scanner 2.4.0
- Rule
- GHSA-48c2-rrv3-qjmp
- File role
- production
- Source
- package-lock.json
Dependency advisory GHSA-38r7-794h-5758 applies
Minor caution · medium confidence
A security scanner found a low-level vulnerability in one of the tools used to build this extension. This is a minor issue that the developer should fix by updating their tools, but it is unlikely to affect users of the extension.
Technical evidence
Scanner reason: OSV-Scanner matched advisory GHSA-38r7-794h-5758 to a dependency declared by this repository.
Contextual assessment: OSV-Scanner matched a low-severity advisory against a dependency in the lockfile. The project's dependency tree is dominated by build-time dev tooling, and the affected package is most likely a transitive dependency of that toolchain. Low-severity advisories in build dependencies for a client-side compiled extension represent minimal risk to end users. Remediation is still good hygiene.
Impact: low · Exploitability: unlikely
Developer action: Run npm audit and update affected dependencies to patched versions. Rebuild and verify the extension still functions correctly.
- Scanner
- osv-scanner 2.4.0
- Rule
- GHSA-38r7-794h-5758
- File role
- production
- Source
- package-lock.json
Dependency advisory GHSA-rgw5-rvv9-x895 applies
Minor caution · medium confidence
A security scanner found a known vulnerability in one of the tools used to build this extension. Since the extension is compiled before distribution, the vulnerable tool likely does not run on the user's machine. The developer should update their build tools to fix it.
Technical evidence
Scanner reason: OSV-Scanner matched advisory GHSA-rgw5-rvv9-x895 to a dependency declared by this repository.
Contextual assessment: OSV-Scanner matched a high-severity advisory against a dependency in the lockfile. The project's production dependencies are react and react-dom, with all other declared dependencies being build-time dev tooling. The affected package is most likely a transitive dependency of the webpack, babel, or eslint toolchain. Since the extension is compiled to a dist bundle before distribution, dev dependencies do not execute in the end user's SillyTavern environment. The advisory should be remediated by updating dependencies but does not indicate malicious behavior or a direct runtime threat to users.
Impact: low · Exploitability: unlikely
Developer action: Run npm audit and update affected dependencies to patched versions. Rebuild and verify the extension still functions correctly.
- Scanner
- osv-scanner 2.4.0
- Rule
- GHSA-rgw5-rvv9-x895
- File role
- production
- Source
- package-lock.json
Expected scanner matches (0)
None.