TavernKeeper Scan Report

SillyTavern/Extension-GroupGreetings

Commit 52e74dd Reviewed

No material or high-risk concern was identified in this review.

This advisory report describes what the named tools and contextual reviewer found at one exact commit. Unknown or unobserved behavior may still exist.

0 high 0 material 14 low

What this review found

No material or high-risk item was identified.

Minor cautions

Dependency advisory GHSA-4x5r-pxfx-6jf8 applies

Minor caution · medium confidence

A scanner found a minor known issue in a package used to build this extension. Since the extension ships a pre-built file and the affected package is likely a building tool, this probably does not affect people who use the extension.

Technical evidence

Scanner reason: OSV-Scanner matched advisory GHSA-4x5r-pxfx-6jf8 to a dependency declared by this repository.

Contextual assessment: OSV-scanner matched a low-severity advisory against a dependency in the lockfile. The project ships a webpack-built bundle (dist/index.js) for a front-end SillyTavern extension. Declared runtime dependencies are lodash, react, and react-dom at current well-maintained versions. The flagged package is most likely a transitive build or dev dependency that does not ship with the extension. The scanner redacted the package name, preventing definitive runtime-vs-dev classification.

Impact: low · Exploitability: unlikely

Developer action: Run npm audit to identify the specific package and update it to a fixed version. If it is a runtime dependency bundled into the shipped output, prioritize the update.

Scanner
osv-scanner 2.4.0
Rule
GHSA-4x5r-pxfx-6jf8
File role
production
Source
package-lock.json

Dependency advisory GHSA-fv7c-fp4j-7gwp applies

Minor caution · medium confidence

A scanner found a serious known issue in a package used during development. Because the extension ships a pre-built file and the affected package is probably a building tool rather than part of the extension itself, this likely does not affect end users.

Technical evidence

Scanner reason: OSV-Scanner matched advisory GHSA-fv7c-fp4j-7gwp to a dependency declared by this repository.

Contextual assessment: OSV-scanner matched a high-severity advisory against a lockfile dependency. The extension's runtime dependencies (lodash ^4.17.23, react ^18.2.0, react-dom ^18.2.0) are at versions with no known high-severity advisories, so the flagged package is most likely a transitive dev or build dependency. The shipped artifact is a webpack bundle that excludes dev tooling. Package name was redacted from scanner output, so exact classification cannot be confirmed.

Impact: low · Exploitability: unlikely

Developer action: Run npm audit to identify the package and update to a fixed version. Confirm whether it is bundled into the shipped output; if so, prioritize remediation.

Scanner
osv-scanner 2.4.0
Rule
GHSA-fv7c-fp4j-7gwp
File role
production
Source
package-lock.json

Dependency advisory GHSA-v2hh-gcrm-f6hx applies

Minor caution · medium confidence

A scanner found a known issue in a development package. The extension delivers a pre-built file, so the affected tool likely does not reach end users.

Technical evidence

Scanner reason: OSV-Scanner matched advisory GHSA-v2hh-gcrm-f6hx to a dependency declared by this repository.

Contextual assessment: OSV-scanner matched a high-severity advisory against a lockfile dependency. The project's three runtime dependencies are at current patched versions, making it unlikely the flagged package is a direct runtime dependency. The extension ships a webpack bundle that does not include dev tooling. Scanner output redacted the package name, preventing definitive confirmation.

Impact: low · Exploitability: unlikely

Developer action: Run npm audit to identify and update the affected package. Verify whether it is included in the shipped bundle.

Scanner
osv-scanner 2.4.0
Rule
GHSA-v2hh-gcrm-f6hx
File role
production
Source
package-lock.json

Dependency advisory GHSA-v39h-62p7-jpjc applies

Minor caution · medium confidence

A scanner found a known issue in a building tool. Since the extension ships a pre-built file, this tool likely does not affect end users.

Technical evidence

Scanner reason: OSV-Scanner matched advisory GHSA-v39h-62p7-jpjc to a dependency declared by this repository.

Contextual assessment: OSV-scanner matched a high-severity advisory against a lockfile dependency. The declared runtime dependencies (lodash, react, react-dom) are at versions without known high-severity vulnerabilities, so the flagged package is most likely a transitive build dependency. The shipped webpack bundle excludes dev tooling. Package identity was redacted from scanner output.

Impact: low · Exploitability: unlikely

Developer action: Run npm audit to identify the package and update it. Confirm whether it is bundled into the shipped output.

Scanner
osv-scanner 2.4.0
Rule
GHSA-v39h-62p7-jpjc
File role
production
Source
package-lock.json

Dependency advisory GHSA-h67p-54hq-rp68 applies

Minor caution · medium confidence

A scanner found a known issue in a development package. The extension ships a pre-built file, so this likely does not affect people who use it.

Technical evidence

Scanner reason: OSV-Scanner matched advisory GHSA-h67p-54hq-rp68 to a dependency declared by this repository.

Contextual assessment: OSV-scanner matched a medium-severity advisory against a lockfile dependency. The runtime dependencies are at current versions without known medium-severity advisories. The flagged package is most likely a transitive dev or build dependency not included in the shipped webpack bundle. Package name was redacted.

Impact: low · Exploitability: unlikely

Developer action: Run npm audit to identify and update the affected package.

Scanner
osv-scanner 2.4.0
Rule
GHSA-h67p-54hq-rp68
File role
production
Source
package-lock.json

Dependency advisory GHSA-q3j6-qgpj-74h6 applies

Minor caution · medium confidence

A scanner found a known issue in a building tool. The extension delivers a pre-built file, so the affected tool probably does not reach end users.

Technical evidence

Scanner reason: OSV-Scanner matched advisory GHSA-q3j6-qgpj-74h6 to a dependency declared by this repository.

Contextual assessment: OSV-scanner matched a high-severity advisory against a lockfile dependency. The three runtime dependencies are at well-maintained versions without matching advisories, so the flagged package is most likely a transitive build dependency excluded from the shipped webpack bundle. Package identity was redacted from scanner output.

Impact: low · Exploitability: unlikely

Developer action: Run npm audit to identify the package and update to a fixed version. Verify whether it is bundled into the shipped output.

Scanner
osv-scanner 2.4.0
Rule
GHSA-q3j6-qgpj-74h6
File role
production
Source
package-lock.json

Dependency advisory GHSA-3jxr-9vmj-r5cp applies

Minor caution · medium confidence

A scanner found a known issue in a development tool. Since the extension ships a pre-built file, this tool likely does not affect end users.

Technical evidence

Scanner reason: OSV-Scanner matched advisory GHSA-3jxr-9vmj-r5cp to a dependency declared by this repository.

Contextual assessment: OSV-scanner matched a high-severity advisory against a lockfile dependency. The runtime dependencies (lodash, react, react-dom) are at current versions without known high-severity vulnerabilities. The flagged package is most likely a transitive dev or build dependency not included in the shipped webpack bundle. Package name was redacted from scanner output.

Impact: low · Exploitability: unlikely

Developer action: Run npm audit to identify and update the affected package. Confirm whether it is bundled into the shipped output.

Scanner
osv-scanner 2.4.0
Rule
GHSA-3jxr-9vmj-r5cp
File role
production
Source
package-lock.json

Dependency advisory GHSA-7p8r-x3mc-p8w7 applies

Minor caution · medium confidence

A scanner found a known issue in a building tool. The extension ships a pre-built file, so the affected tool probably does not reach end users.

Technical evidence

Scanner reason: OSV-Scanner matched advisory GHSA-7p8r-x3mc-p8w7 to a dependency declared by this repository.

Contextual assessment: OSV-scanner matched a high-severity advisory against a lockfile dependency. The declared runtime dependencies are at current patched versions without matching advisories. The flagged package is most likely a transitive build dependency excluded from the shipped webpack bundle. Package identity was redacted from scanner output.

Impact: low · Exploitability: unlikely

Developer action: Run npm audit to identify the package and update to a fixed version. Verify whether it is bundled into the shipped output.

Scanner
osv-scanner 2.4.0
Rule
GHSA-7p8r-x3mc-p8w7
File role
production
Source
package-lock.json

Dependency advisory GHSA-4c8g-83qw-93j6 applies

Minor caution · medium confidence

A known security issue was found in a tool used to build this extension, not in the extension itself. The tools that compile the code are separate from what users actually install, so this does not affect people using the extension.

Technical evidence

Scanner reason: OSV-Scanner matched advisory GHSA-4c8g-83qw-93j6 to a dependency declared by this repository.

Contextual assessment: The advisory matches a dependency declared in the lockfile for a webpack-bundled browser extension. The project's direct runtime dependencies (lodash, react, react-dom) are at recent versions with no matching high-severity advisories. The flagged package is part of the build toolchain (babel, webpack, or eslint-config-react-app transitive tree), which is used only during npm run build and does not ship in the distributed dist/index.js artifact. The vulnerability affects the developer build environment, not extension end users.

Impact: low · Exploitability: unlikely

Developer action: Update devDependencies (especially eslint-config-react-app and the babel/webpack toolchain) to newer versions that resolve known advisories and reduce supply-chain risk to the build process.

Scanner
osv-scanner 2.4.0
Rule
GHSA-4c8g-83qw-93j6
File role
production
Source
package-lock.json

Dependency advisory GHSA-52cp-r559-cp3m applies

Minor caution · medium confidence

A known security issue was found in a build tool for this extension, not in the extension that users install. This does not affect people using the extension.

Technical evidence

Scanner reason: OSV-Scanner matched advisory GHSA-52cp-r559-cp3m to a dependency declared by this repository.

Contextual assessment: The advisory matches a transitive dependency in the lockfile. The project ships only the webpack-bundled dist/index.js per its manifest. Direct runtime dependencies are lodash, react, and react-dom at versions without matching high-severity advisories. This flagged package belongs to the build-time dependency tree (babel, webpack, or eslint-config-react-app transitives) and is not included in the shipped artifact. The risk is confined to the developer build environment.

Impact: low · Exploitability: unlikely

Developer action: Refresh devDependencies to resolve known advisories in the build toolchain and reduce supply-chain exposure during development.

Scanner
osv-scanner 2.4.0
Rule
GHSA-52cp-r559-cp3m
File role
production
Source
package-lock.json

Dependency advisory GHSA-mh99-v99m-4gvg applies

Minor caution · medium confidence

A known security issue was found in a development tool used to compile this extension. The tool is not part of what users install, so this does not affect extension users.

Technical evidence

Scanner reason: OSV-Scanner matched advisory GHSA-mh99-v99m-4gvg to a dependency declared by this repository.

Contextual assessment: The advisory matches a dependency in the lockfile for a project that distributes a webpack-bundled browser extension. The runtime dependencies (lodash, react, react-dom) are at current versions without matching advisories. The flagged package is in the build-only dependency tree and does not appear in the shipped dist/index.js. End users of the extension are not exposed to this vulnerability.

Impact: low · Exploitability: unlikely

Developer action: Update build-time dependencies to versions that resolve the advisory and minimize supply-chain risk to the build environment.

Scanner
osv-scanner 2.4.0
Rule
GHSA-mh99-v99m-4gvg
File role
production
Source
package-lock.json

Dependency advisory GHSA-rgw5-rvv9-x895 applies

Minor caution · medium confidence

A known security issue was found in a tool used to build this extension, not in the extension itself. Since users only install the compiled extension file, this does not affect them.

Technical evidence

Scanner reason: OSV-Scanner matched advisory GHSA-rgw5-rvv9-x895 to a dependency declared by this repository.

Contextual assessment: The advisory matches a lockfile dependency for a webpack-bundled SillyTavern extension. The shipped artifact is dist/index.js per the manifest. Direct runtime dependencies are at recent versions without matching high-severity advisories. The flagged package is part of the build toolchain (babel, webpack, or eslint-config-react-app transitive tree) and is not bundled into the runtime artifact. The vulnerability impacts only the developer build environment, not extension end users.

Impact: low · Exploitability: unlikely

Developer action: Update devDependencies to resolve known advisories in the build toolchain and reduce supply-chain risk during development.

Scanner
osv-scanner 2.4.0
Rule
GHSA-rgw5-rvv9-x895
File role
production
Source
package-lock.json
Expected scanner matches (2)

OpenGrep reported tavernkeeper.dynamic-execution.javascript-eval

Expected behavior · high confidence

The flagged code is a standard programming pattern used by build tools to detect the global environment. It does not run any user or remote input and is not a security risk.

Technical evidence

Scanner reason: OpenGrep matched static-analysis rule tavernkeeper.dynamic-execution.javascript-eval in this repository.

Contextual assessment: The scanner matched a dynamic-execution pattern on the bundled extension's runtime line. The relevant construct is the webpack runtime's global-object detection idiom (Function("return this")()), which is a standard, hardcoded pattern used to obtain the global scope. No user-supplied or remote input is passed to any dynamic execution primitive. The extension's actual logic on this line consists of React rendering, SillyTavern context API calls, fetch requests to the local /api/characters/merge-attributes endpoint, and lodash utility usage — none of which involve eval or Function with untrusted data.

Impact: none · Exploitability: unlikely

Developer action: none

Scanner
opengrep 1.26.0
Rule
tavernkeeper.dynamic-execution.javascript-eval
File role
generated
Source
dist/index.js:45

OpenGrep reported tavernkeeper.dynamic-execution.javascript-eval

Expected behavior · high confidence

The flagged code is inside the popular Lodash utility library and uses a standard, hardcoded pattern to find the global environment. It does not process any user input and poses no security risk.

Technical evidence

Scanner reason: OpenGrep matched static-analysis rule tavernkeeper.dynamic-execution.javascript-eval in this repository.

Contextual assessment: The scanner matched a dynamic-execution pattern within the bundled Lodash library (module 543). Lodash uses Function("return this")() as a well-known, hardcoded idiom to detect the global object across environments. No user-supplied, remote, or character-card input is passed to this construct. It is a static expression evaluated once at library initialization and is not reachable as an injection vector.

Impact: none · Exploitability: unlikely

Developer action: none

Scanner
opengrep 1.26.0
Rule
tavernkeeper.dynamic-execution.javascript-eval
File role
generated
Source
dist/index.js:9

Coverage and limitations

Tools

Limitations

Technical scan identity