What this review found
No material or immediate-danger item was identified.
Minor cautions
Dependency advisory GHSA-qj8w-gfj5-8c6v applies
Minor caution · low confidence
A scanner flagged a dependency with a known security issue. This extension ships pre-built files, so the flagged dependency is most likely a build tool that never runs on users' machines. No concrete harm to extension users is evident.
Technical evidence
Scanner reason: OSV-Scanner matched advisory GHSA-qj8w-gfj5-8c6v to a dependency declared by this repository.
Contextual assessment: OSV-scanner matched a medium-severity advisory against a dependency declared in this lockfile. The project ships a committed dist artifact and declares only one runtime dependency (sillytavern-utils-lib). All other visible lockfile entries are dev or peer dependencies used for building. Package details were removed from the advisory, so the exact affected package and version cannot be confirmed from the supplied evidence, but the project structure indicates the vulnerable code is most likely in build-time tooling with no runtime reachability for end users who install the pre-built extension.
Impact: none · Exploitability: unlikely
Developer action: Update dev dependencies to their latest patched versions when convenient to keep the build environment current.
- Scanner
- osv-scanner 2.4.0
- Rule
- GHSA-qj8w-gfj5-8c6v
- File role
- production
- Source
- package-lock.json
Dependency advisory GHSA-5c6j-r48x-rmvq applies
Minor caution · low confidence
A scanner flagged a dependency with a high-severity label. Because this extension ships ready-to-use files and the flagged dependency appears to be a build tool, it likely never runs on users' machines. The severity label alone does not establish user-facing danger here.
Technical evidence
Scanner reason: OSV-Scanner matched advisory GHSA-5c6j-r48x-rmvq to a dependency declared by this repository.
Contextual assessment: OSV-scanner matched a high-severity advisory against a dependency in this lockfile. The project commits its dist output and has a single runtime dependency (sillytavern-utils-lib). The visible lockfile entries are all dev or peer dependencies for the webpack/typescript build chain. With package details removed, the exact affected package cannot be confirmed, but the project structure strongly suggests the advisory targets build-only tooling that does not ship to or execute for end users.
Impact: none · Exploitability: unlikely
Developer action: Update dev dependencies to their latest patched versions when convenient to keep the build environment current.
- Scanner
- osv-scanner 2.4.0
- Rule
- GHSA-5c6j-r48x-rmvq
- File role
- production
- Source
- package-lock.json
Dependency advisory GHSA-v2hh-gcrm-f6hx applies
Minor caution · low confidence
A scanner flagged a dependency with a high-severity label. This extension ships pre-built files, so the flagged dependency is most likely a build tool that never runs on users' machines. No concrete user harm is evident.
Technical evidence
Scanner reason: OSV-Scanner matched advisory GHSA-v2hh-gcrm-f6hx to a dependency declared by this repository.
Contextual assessment: OSV-scanner matched a high-severity advisory against a dependency in this lockfile. The project ships a committed dist build and declares only sillytavern-utils-lib as a runtime dependency. All visible lockfile packages are dev or peer dependencies for the build toolchain. Package details were removed from the advisory, preventing exact identification, but the evidence available indicates no runtime reachability for extension end users.
Impact: none · Exploitability: unlikely
Developer action: Update dev dependencies to their latest patched versions when convenient to keep the build environment current.
- Scanner
- osv-scanner 2.4.0
- Rule
- GHSA-v2hh-gcrm-f6hx
- File role
- production
- Source
- package-lock.json
Dependency advisory GHSA-v39h-62p7-jpjc applies
Minor caution · low confidence
A scanner flagged a dependency with a high-severity label. Because this extension ships ready-to-use files and the flagged dependency appears to be a build tool, it likely never runs on users' machines.
Technical evidence
Scanner reason: OSV-Scanner matched advisory GHSA-v39h-62p7-jpjc to a dependency declared by this repository.
Contextual assessment: OSV-scanner matched a high-severity advisory against a dependency in this lockfile. The project commits its dist output and has a single runtime dependency (sillytavern-utils-lib). Visible lockfile entries are dev or peer dependencies for the webpack and typescript build chain. With package details removed, the exact affected package cannot be confirmed, but the project structure indicates the advisory most likely targets build-only tooling with no runtime reachability for end users.
Impact: none · Exploitability: unlikely
Developer action: Update dev dependencies to their latest patched versions when convenient to keep the build environment current.
- Scanner
- osv-scanner 2.4.0
- Rule
- GHSA-v39h-62p7-jpjc
- File role
- production
- Source
- package-lock.json
Dependency advisory GHSA-q3j6-qgpj-74h6 applies
Minor caution · low confidence
A scanner flagged a dependency with a high-severity label. This extension ships pre-built files, so the flagged dependency is most likely a build tool that never runs on users' machines.
Technical evidence
Scanner reason: OSV-Scanner matched advisory GHSA-q3j6-qgpj-74h6 to a dependency declared by this repository.
Contextual assessment: OSV-scanner matched a high-severity advisory against a dependency in this lockfile. The project ships a committed dist build and declares only sillytavern-utils-lib as a runtime dependency. All visible lockfile packages are dev or peer dependencies for the build toolchain. Package details were removed from the advisory, preventing exact identification, but the available evidence indicates no runtime reachability for extension end users.
Impact: none · Exploitability: unlikely
Developer action: Update dev dependencies to their latest patched versions when convenient to keep the build environment current.
- Scanner
- osv-scanner 2.4.0
- Rule
- GHSA-q3j6-qgpj-74h6
- File role
- production
- Source
- package-lock.json
Dependency advisory GHSA-7p8r-x3mc-p8w7 applies
Minor caution · low confidence
A scanner flagged a dependency with a high-severity label. Because this extension ships ready-to-use files and the flagged dependency appears to be a build tool, it likely never runs on users' machines.
Technical evidence
Scanner reason: OSV-Scanner matched advisory GHSA-7p8r-x3mc-p8w7 to a dependency declared by this repository.
Contextual assessment: OSV-scanner matched a high-severity advisory against a dependency in this lockfile. The project commits its dist output and has a single runtime dependency (sillytavern-utils-lib). Visible lockfile entries are dev or peer dependencies for the webpack and typescript build chain. With package details removed, the exact affected package cannot be confirmed, but the project structure indicates the advisory most likely targets build-only tooling with no runtime reachability for end users.
Impact: none · Exploitability: unlikely
Developer action: Update dev dependencies to their latest patched versions when convenient to keep the build environment current.
- Scanner
- osv-scanner 2.4.0
- Rule
- GHSA-7p8r-x3mc-p8w7
- File role
- production
- Source
- package-lock.json
Dependency advisory GHSA-6g55-p6wh-862q applies
Minor caution · low confidence
A scanner flagged a dependency with a high-severity label. This extension ships pre-built files, so the flagged dependency is most likely a build tool that never runs on users' machines.
Technical evidence
Scanner reason: OSV-Scanner matched advisory GHSA-6g55-p6wh-862q to a dependency declared by this repository.
Contextual assessment: OSV-scanner matched a high-severity advisory against a dependency in this lockfile. The project ships a committed dist build and declares only sillytavern-utils-lib as a runtime dependency. All visible lockfile packages are dev or peer dependencies for the build toolchain. Package details were removed from the advisory, preventing exact identification, but the available evidence indicates no runtime reachability for extension end users.
Impact: none · Exploitability: unlikely
Developer action: Update dev dependencies to their latest patched versions when convenient to keep the build environment current.
- Scanner
- osv-scanner 2.4.0
- Rule
- GHSA-6g55-p6wh-862q
- File role
- production
- Source
- package-lock.json
Dependency advisory GHSA-r28c-9q8g-f849 applies
Minor caution · low confidence
A scanner flagged a dependency with a high-severity label. Because this extension ships ready-to-use files and the flagged dependency appears to be a build tool, it likely never runs on users' machines.
Technical evidence
Scanner reason: OSV-Scanner matched advisory GHSA-r28c-9q8g-f849 to a dependency declared by this repository.
Contextual assessment: OSV-scanner matched a high-severity advisory against a dependency in this lockfile. The project commits its dist output and has a single runtime dependency (sillytavern-utils-lib). Visible lockfile entries are dev or peer dependencies for the webpack and typescript build chain. With package details removed, the exact affected package cannot be confirmed, but the project structure indicates the advisory most likely targets build-only tooling with no runtime reachability for end users.
Impact: none · Exploitability: unlikely
Developer action: Update dev dependencies to their latest patched versions when convenient to keep the build environment current.
- Scanner
- osv-scanner 2.4.0
- Rule
- GHSA-r28c-9q8g-f849
- File role
- production
- Source
- package-lock.json
Dependency advisory GHSA-3v7f-55p6-f55p applies
Minor caution · medium confidence
A security scanner found a medium-severity vulnerability in one of the project's dependencies. Since the project ships pre-built files and users don't run the build tools, most of these dependencies never run on user machines. Without knowing exactly which package is affected, the real-world risk to users appears low.
Technical evidence
Scanner reason: OSV-Scanner matched advisory GHSA-3v7f-55p6-f55p to a dependency declared by this repository.
Contextual assessment: OSV-scanner matched a medium-severity advisory against a dependency in the lockfile. The project has one production dependency (sillytavern-utils-lib) and several dev dependencies (webpack, ts-loader, typescript, webpack-cli). The README states dist is committed, so end users install the pre-built output and never run the build toolchain. The visible lockfile entries are predominantly dev or peer dependencies with no runtime path in the shipped extension. Package details were removed from the scanner output, preventing definitive mapping of this advisory to a specific package and confirmation of runtime reachability. If the advisory targets a dev-only dependency, there is no impact on end users. If it targets a transitive dependency of sillytavern-utils-lib, runtime reachability and attacker-controlled input paths remain unclear from the supplied evidence.
Impact: low · Exploitability: unlikely
Developer action: Update affected dependencies to patched versions during the next build cycle. No urgent action is required for end-user safety.
- Scanner
- osv-scanner 2.4.0
- Rule
- GHSA-3v7f-55p6-f55p
- File role
- production
- Source
- package-lock.json
Dependency advisory GHSA-4c8g-83qw-93j6 applies
Minor caution · medium confidence
A scanner flagged a high-severity vulnerability in a dependency, but the project ships pre-built files to users. Most flagged dependencies are build tools that never run on user machines. Without knowing the exact package, the practical risk to users is likely low, though the developer should still update dependencies.
Technical evidence
Scanner reason: OSV-Scanner matched advisory GHSA-4c8g-83qw-93j6 to a dependency declared by this repository.
Contextual assessment: OSV-scanner matched a high-severity advisory against a dependency in the lockfile. Despite the high scanner severity, the project commits its dist output and end users do not execute build tooling. The visible lockfile entries are almost entirely dev or peer dependencies (webpack ecosystem, babel, vue compiler, typescript types). The only production dependency is sillytavern-utils-lib. Scanner package details were removed, so the specific affected package and whether it is a dev or production dependency cannot be confirmed. If this advisory targets a build-time dependency, the vulnerable code has no runtime reachability in the shipped extension. If it targets a production transitive dependency, the supplied evidence does not show attacker-controlled input reaching the vulnerable code path.
Impact: low · Exploitability: unlikely
Developer action: Identify the specific package flagged by this advisory and update it to a patched version. Prioritize this if the package is a runtime dependency of sillytavern-utils-lib rather than a build tool.
- Scanner
- osv-scanner 2.4.0
- Rule
- GHSA-4c8g-83qw-93j6
- File role
- production
- Source
- package-lock.json
Dependency advisory GHSA-qx2v-qp2m-jg93 applies
Minor caution · medium confidence
A scanner found a medium-severity vulnerability in a project dependency. Since users get pre-built files and don't run build tools, the risk is likely low. The developer should still update the affected package.
Technical evidence
Scanner reason: OSV-Scanner matched advisory GHSA-qx2v-qp2m-jg93 to a dependency declared by this repository.
Contextual assessment: OSV-scanner matched a medium-severity advisory against a dependency in the lockfile. The project commits dist and users do not run build tooling. The visible lockfile content shows dev and peer dependencies only. The sole production dependency is sillytavern-utils-lib. Package details were removed from the scanner output, preventing confirmation of whether the affected package is a dev or production dependency. For dev dependencies, the vulnerable code is not present in the shipped extension. For production dependencies, the evidence does not demonstrate runtime reachability or attacker-controlled input.
Impact: low · Exploitability: unlikely
Developer action: Update the affected dependency to a patched version during the next maintenance cycle.
- Scanner
- osv-scanner 2.4.0
- Rule
- GHSA-qx2v-qp2m-jg93
- File role
- production
- Source
- package-lock.json
Dependency advisory GHSA-fxqj-rqcc-2cmp applies
Minor caution · medium confidence
A scanner found a medium-severity vulnerability in a dependency. The project ships pre-built files, so most dependencies don't run on user machines. The practical risk appears low.
Technical evidence
Scanner reason: OSV-Scanner matched advisory GHSA-fxqj-rqcc-2cmp to a dependency declared by this repository.
Contextual assessment: OSV-scanner matched a medium-severity advisory against a dependency in the lockfile. The project ships pre-built dist output, so build-time dependencies do not execute on end-user machines. The visible lockfile entries are dev or peer dependencies. The only production dependency is sillytavern-utils-lib. Scanner package details were removed, so the specific affected package cannot be confirmed. Without that mapping, runtime reachability and attacker input paths cannot be fully assessed, but the evidence does not indicate a reachable vulnerability in the shipped extension.
Impact: low · Exploitability: unlikely
Developer action: Update the affected dependency to a patched version when convenient.
- Scanner
- osv-scanner 2.4.0
- Rule
- GHSA-fxqj-rqcc-2cmp
- File role
- production
- Source
- package-lock.json
Dependency advisory GHSA-c2c7-rcm5-vvqj applies
Minor caution · medium confidence
A scanner flagged a high-severity vulnerability in a dependency, but the project ships pre-built files. Most dependencies are build tools that never run on user machines. Without knowing the exact package, the practical risk to users is likely low, though the developer should investigate and update.
Technical evidence
Scanner reason: OSV-Scanner matched advisory GHSA-c2c7-rcm5-vvqj to a dependency declared by this repository.
Contextual assessment: OSV-scanner matched a high-severity advisory against a dependency in the lockfile. The project commits dist and users do not run build tooling. The visible lockfile content consists of dev and peer dependencies. The only production dependency is sillytavern-utils-lib. Package details were removed from the scanner output, preventing definitive identification of the affected package. If the advisory targets a build-time dependency, the vulnerable code has no runtime path in the shipped extension. If it targets a production transitive dependency, the supplied evidence does not show attacker-controlled input reaching the vulnerable code. Advisory severity alone does not establish immediate danger without runtime reachability.
Impact: low · Exploitability: unlikely
Developer action: Identify the specific package flagged by this advisory and update it to a patched version. If the package is a runtime dependency of sillytavern-utils-lib, prioritize the update.
- Scanner
- osv-scanner 2.4.0
- Rule
- GHSA-c2c7-rcm5-vvqj
- File role
- production
- Source
- package-lock.json
Expected scanner matches (5)
OpenGrep reported tavernkeeper.dynamic-execution.javascript-eval
Expected behavior · high confidence
The extension uses a standard technique to access SillyTavern's own internal script so it can refresh the chat display after updating summary notes. The target is a fixed internal application file, not anything user-controlled or external, and the only action taken is a screen refresh.
Technical evidence
Scanner reason: OpenGrep matched static-analysis rule tavernkeeper.dynamic-execution.javascript-eval in this repository.
Contextual assessment: Detailed technical wording was omitted by the public report safety filter.
Impact: none · Exploitability: unlikely
Developer action: none
- Scanner
- opengrep 1.26.0
- Rule
- tavernkeeper.dynamic-execution.javascript-eval
- File role
- production
- Source
- src/index.ts:2908
OpenGrep reported tavernkeeper.dynamic-execution.javascript-eval
Expected behavior · high confidence
The code uses a dynamic execution technique to load a built-in SillyTavern module. The code being executed is a fixed, hardcoded instruction with no user input involved. This is a standard workaround used by SillyTavern extensions to access the host application's internal features.
Technical evidence
Scanner reason: OpenGrep matched static-analysis rule tavernkeeper.dynamic-execution.javascript-eval in this repository.
Contextual assessment: Detailed technical wording was omitted by the public report safety filter.
Impact: none · Exploitability: unlikely
Developer action: none
- Scanner
- opengrep 1.26.0
- Rule
- tavernkeeper.dynamic-execution.javascript-eval
- File role
- production
- Source
- src/index.ts:435
OpenGrep reported tavernkeeper.dynamic-execution.javascript-eval
Expected behavior · high confidence
The code uses a dynamic execution technique to load SillyTavern's main internal script. The instruction is hardcoded with no user input involved. This is a standard workaround for extensions to read configuration values from the host application.
Technical evidence
Scanner reason: OpenGrep matched static-analysis rule tavernkeeper.dynamic-execution.javascript-eval in this repository.
Contextual assessment: Detailed technical wording was omitted by the public report safety filter.
Impact: none · Exploitability: unlikely
Developer action: none
- Scanner
- opengrep 1.26.0
- Rule
- tavernkeeper.dynamic-execution.javascript-eval
- File role
- production
- Source
- src/index.ts:444
OpenGrep reported tavernkeeper.dynamic-execution.javascript-eval
Expected behavior · high confidence
The code uses a dynamic function to load a built-in SillyTavern script module so the extension can inject tracker information into prompts. The loaded path is hardcoded and local to SillyTavern, not something a user or attacker controls. This matches the extension's advertised prompt injection feature.
Technical evidence
Scanner reason: OpenGrep matched static-analysis rule tavernkeeper.dynamic-execution.javascript-eval in this repository.
Contextual assessment: Detailed technical wording was omitted by the public report safety filter.
Impact: none · Exploitability: unlikely
Developer action: none
- Scanner
- opengrep 1.26.0
- Rule
- tavernkeeper.dynamic-execution.javascript-eval
- File role
- production
- Source
- src/promptInjection.ts:687
OpenGrep reported tavernkeeper.dynamic-execution.javascript-eval
Expected behavior · high confidence
The code uses a dynamic execution feature only to load a built-in SillyTavern module so the extension can save its settings through the normal SillyTavern settings system. The code that runs is fixed and not influenced by any user input, so there is no security risk here.
Technical evidence
Scanner reason: OpenGrep matched static-analysis rule tavernkeeper.dynamic-execution.javascript-eval in this repository.
Contextual assessment: Detailed technical wording was omitted by the public report safety filter.
Impact: none · Exploitability: unlikely
Developer action: none
- Scanner
- opengrep 1.26.0
- Rule
- tavernkeeper.dynamic-execution.javascript-eval
- File role
- production
- Source
- src/settings.ts:528