What this review found
No material or high-risk item was identified.
Minor cautions
Dependency advisory GHSA-4x5r-pxfx-6jf8 applies
Minor caution · medium confidence
A scanner found a minor known issue in a package used to build this extension. Since the extension ships a pre-built file and the affected package is likely a building tool, this probably does not affect people who use the extension.
Technical evidence
Scanner reason: OSV-Scanner matched advisory GHSA-4x5r-pxfx-6jf8 to a dependency declared by this repository.
Contextual assessment: OSV-scanner matched a low-severity advisory against a dependency in the lockfile. The project ships a webpack-built bundle (dist/index.js) for a front-end SillyTavern extension. Declared runtime dependencies are lodash, react, and react-dom at current well-maintained versions. The flagged package is most likely a transitive build or dev dependency that does not ship with the extension. The scanner redacted the package name, preventing definitive runtime-vs-dev classification.
Impact: low · Exploitability: unlikely
Developer action: Run npm audit to identify the specific package and update it to a fixed version. If it is a runtime dependency bundled into the shipped output, prioritize the update.
- Scanner
- osv-scanner 2.4.0
- Rule
- GHSA-4x5r-pxfx-6jf8
- File role
- production
- Source
- package-lock.json
Dependency advisory GHSA-fv7c-fp4j-7gwp applies
Minor caution · medium confidence
A scanner found a serious known issue in a package used during development. Because the extension ships a pre-built file and the affected package is probably a building tool rather than part of the extension itself, this likely does not affect end users.
Technical evidence
Scanner reason: OSV-Scanner matched advisory GHSA-fv7c-fp4j-7gwp to a dependency declared by this repository.
Contextual assessment: OSV-scanner matched a high-severity advisory against a lockfile dependency. The extension's runtime dependencies (lodash ^4.17.23, react ^18.2.0, react-dom ^18.2.0) are at versions with no known high-severity advisories, so the flagged package is most likely a transitive dev or build dependency. The shipped artifact is a webpack bundle that excludes dev tooling. Package name was redacted from scanner output, so exact classification cannot be confirmed.
Impact: low · Exploitability: unlikely
Developer action: Run npm audit to identify the package and update to a fixed version. Confirm whether it is bundled into the shipped output; if so, prioritize remediation.
- Scanner
- osv-scanner 2.4.0
- Rule
- GHSA-fv7c-fp4j-7gwp
- File role
- production
- Source
- package-lock.json
Dependency advisory GHSA-v2hh-gcrm-f6hx applies
Minor caution · medium confidence
A scanner found a known issue in a development package. The extension delivers a pre-built file, so the affected tool likely does not reach end users.
Technical evidence
Scanner reason: OSV-Scanner matched advisory GHSA-v2hh-gcrm-f6hx to a dependency declared by this repository.
Contextual assessment: OSV-scanner matched a high-severity advisory against a lockfile dependency. The project's three runtime dependencies are at current patched versions, making it unlikely the flagged package is a direct runtime dependency. The extension ships a webpack bundle that does not include dev tooling. Scanner output redacted the package name, preventing definitive confirmation.
Impact: low · Exploitability: unlikely
Developer action: Run npm audit to identify and update the affected package. Verify whether it is included in the shipped bundle.
- Scanner
- osv-scanner 2.4.0
- Rule
- GHSA-v2hh-gcrm-f6hx
- File role
- production
- Source
- package-lock.json
Dependency advisory GHSA-v39h-62p7-jpjc applies
Minor caution · medium confidence
A scanner found a known issue in a building tool. Since the extension ships a pre-built file, this tool likely does not affect end users.
Technical evidence
Scanner reason: OSV-Scanner matched advisory GHSA-v39h-62p7-jpjc to a dependency declared by this repository.
Contextual assessment: OSV-scanner matched a high-severity advisory against a lockfile dependency. The declared runtime dependencies (lodash, react, react-dom) are at versions without known high-severity vulnerabilities, so the flagged package is most likely a transitive build dependency. The shipped webpack bundle excludes dev tooling. Package identity was redacted from scanner output.
Impact: low · Exploitability: unlikely
Developer action: Run npm audit to identify the package and update it. Confirm whether it is bundled into the shipped output.
- Scanner
- osv-scanner 2.4.0
- Rule
- GHSA-v39h-62p7-jpjc
- File role
- production
- Source
- package-lock.json
Dependency advisory GHSA-h67p-54hq-rp68 applies
Minor caution · medium confidence
A scanner found a known issue in a development package. The extension ships a pre-built file, so this likely does not affect people who use it.
Technical evidence
Scanner reason: OSV-Scanner matched advisory GHSA-h67p-54hq-rp68 to a dependency declared by this repository.
Contextual assessment: OSV-scanner matched a medium-severity advisory against a lockfile dependency. The runtime dependencies are at current versions without known medium-severity advisories. The flagged package is most likely a transitive dev or build dependency not included in the shipped webpack bundle. Package name was redacted.
Impact: low · Exploitability: unlikely
Developer action: Run npm audit to identify and update the affected package.
- Scanner
- osv-scanner 2.4.0
- Rule
- GHSA-h67p-54hq-rp68
- File role
- production
- Source
- package-lock.json
Dependency advisory GHSA-q3j6-qgpj-74h6 applies
Minor caution · medium confidence
A scanner found a known issue in a building tool. The extension delivers a pre-built file, so the affected tool probably does not reach end users.
Technical evidence
Scanner reason: OSV-Scanner matched advisory GHSA-q3j6-qgpj-74h6 to a dependency declared by this repository.
Contextual assessment: OSV-scanner matched a high-severity advisory against a lockfile dependency. The three runtime dependencies are at well-maintained versions without matching advisories, so the flagged package is most likely a transitive build dependency excluded from the shipped webpack bundle. Package identity was redacted from scanner output.
Impact: low · Exploitability: unlikely
Developer action: Run npm audit to identify the package and update to a fixed version. Verify whether it is bundled into the shipped output.
- Scanner
- osv-scanner 2.4.0
- Rule
- GHSA-q3j6-qgpj-74h6
- File role
- production
- Source
- package-lock.json
Dependency advisory GHSA-3jxr-9vmj-r5cp applies
Minor caution · medium confidence
A scanner found a known issue in a development tool. Since the extension ships a pre-built file, this tool likely does not affect end users.
Technical evidence
Scanner reason: OSV-Scanner matched advisory GHSA-3jxr-9vmj-r5cp to a dependency declared by this repository.
Contextual assessment: OSV-scanner matched a high-severity advisory against a lockfile dependency. The runtime dependencies (lodash, react, react-dom) are at current versions without known high-severity vulnerabilities. The flagged package is most likely a transitive dev or build dependency not included in the shipped webpack bundle. Package name was redacted from scanner output.
Impact: low · Exploitability: unlikely
Developer action: Run npm audit to identify and update the affected package. Confirm whether it is bundled into the shipped output.
- Scanner
- osv-scanner 2.4.0
- Rule
- GHSA-3jxr-9vmj-r5cp
- File role
- production
- Source
- package-lock.json
Dependency advisory GHSA-7p8r-x3mc-p8w7 applies
Minor caution · medium confidence
A scanner found a known issue in a building tool. The extension ships a pre-built file, so the affected tool probably does not reach end users.
Technical evidence
Scanner reason: OSV-Scanner matched advisory GHSA-7p8r-x3mc-p8w7 to a dependency declared by this repository.
Contextual assessment: OSV-scanner matched a high-severity advisory against a lockfile dependency. The declared runtime dependencies are at current patched versions without matching advisories. The flagged package is most likely a transitive build dependency excluded from the shipped webpack bundle. Package identity was redacted from scanner output.
Impact: low · Exploitability: unlikely
Developer action: Run npm audit to identify the package and update to a fixed version. Verify whether it is bundled into the shipped output.
- Scanner
- osv-scanner 2.4.0
- Rule
- GHSA-7p8r-x3mc-p8w7
- File role
- production
- Source
- package-lock.json
Dependency advisory GHSA-4c8g-83qw-93j6 applies
Minor caution · medium confidence
A known security issue was found in a tool used to build this extension, not in the extension itself. The tools that compile the code are separate from what users actually install, so this does not affect people using the extension.
Technical evidence
Scanner reason: OSV-Scanner matched advisory GHSA-4c8g-83qw-93j6 to a dependency declared by this repository.
Contextual assessment: The advisory matches a dependency declared in the lockfile for a webpack-bundled browser extension. The project's direct runtime dependencies (lodash, react, react-dom) are at recent versions with no matching high-severity advisories. The flagged package is part of the build toolchain (babel, webpack, or eslint-config-react-app transitive tree), which is used only during npm run build and does not ship in the distributed dist/index.js artifact. The vulnerability affects the developer build environment, not extension end users.
Impact: low · Exploitability: unlikely
Developer action: Update devDependencies (especially eslint-config-react-app and the babel/webpack toolchain) to newer versions that resolve known advisories and reduce supply-chain risk to the build process.
- Scanner
- osv-scanner 2.4.0
- Rule
- GHSA-4c8g-83qw-93j6
- File role
- production
- Source
- package-lock.json
Dependency advisory GHSA-52cp-r559-cp3m applies
Minor caution · medium confidence
A known security issue was found in a build tool for this extension, not in the extension that users install. This does not affect people using the extension.
Technical evidence
Scanner reason: OSV-Scanner matched advisory GHSA-52cp-r559-cp3m to a dependency declared by this repository.
Contextual assessment: The advisory matches a transitive dependency in the lockfile. The project ships only the webpack-bundled dist/index.js per its manifest. Direct runtime dependencies are lodash, react, and react-dom at versions without matching high-severity advisories. This flagged package belongs to the build-time dependency tree (babel, webpack, or eslint-config-react-app transitives) and is not included in the shipped artifact. The risk is confined to the developer build environment.
Impact: low · Exploitability: unlikely
Developer action: Refresh devDependencies to resolve known advisories in the build toolchain and reduce supply-chain exposure during development.
- Scanner
- osv-scanner 2.4.0
- Rule
- GHSA-52cp-r559-cp3m
- File role
- production
- Source
- package-lock.json
Dependency advisory GHSA-mh99-v99m-4gvg applies
Minor caution · medium confidence
A known security issue was found in a development tool used to compile this extension. The tool is not part of what users install, so this does not affect extension users.
Technical evidence
Scanner reason: OSV-Scanner matched advisory GHSA-mh99-v99m-4gvg to a dependency declared by this repository.
Contextual assessment: The advisory matches a dependency in the lockfile for a project that distributes a webpack-bundled browser extension. The runtime dependencies (lodash, react, react-dom) are at current versions without matching advisories. The flagged package is in the build-only dependency tree and does not appear in the shipped dist/index.js. End users of the extension are not exposed to this vulnerability.
Impact: low · Exploitability: unlikely
Developer action: Update build-time dependencies to versions that resolve the advisory and minimize supply-chain risk to the build environment.
- Scanner
- osv-scanner 2.4.0
- Rule
- GHSA-mh99-v99m-4gvg
- File role
- production
- Source
- package-lock.json
Dependency advisory GHSA-rgw5-rvv9-x895 applies
Minor caution · medium confidence
A known security issue was found in a tool used to build this extension, not in the extension itself. Since users only install the compiled extension file, this does not affect them.
Technical evidence
Scanner reason: OSV-Scanner matched advisory GHSA-rgw5-rvv9-x895 to a dependency declared by this repository.
Contextual assessment: The advisory matches a lockfile dependency for a webpack-bundled SillyTavern extension. The shipped artifact is dist/index.js per the manifest. Direct runtime dependencies are at recent versions without matching high-severity advisories. The flagged package is part of the build toolchain (babel, webpack, or eslint-config-react-app transitive tree) and is not bundled into the runtime artifact. The vulnerability impacts only the developer build environment, not extension end users.
Impact: low · Exploitability: unlikely
Developer action: Update devDependencies to resolve known advisories in the build toolchain and reduce supply-chain risk during development.
- Scanner
- osv-scanner 2.4.0
- Rule
- GHSA-rgw5-rvv9-x895
- File role
- production
- Source
- package-lock.json
Expected scanner matches (2)
OpenGrep reported tavernkeeper.dynamic-execution.javascript-eval
Expected behavior · high confidence
The flagged code is a standard programming pattern used by build tools to detect the global environment. It does not run any user or remote input and is not a security risk.
Technical evidence
Scanner reason: OpenGrep matched static-analysis rule tavernkeeper.dynamic-execution.javascript-eval in this repository.
Contextual assessment: The scanner matched a dynamic-execution pattern on the bundled extension's runtime line. The relevant construct is the webpack runtime's global-object detection idiom (Function("return this")()), which is a standard, hardcoded pattern used to obtain the global scope. No user-supplied or remote input is passed to any dynamic execution primitive. The extension's actual logic on this line consists of React rendering, SillyTavern context API calls, fetch requests to the local /api/characters/merge-attributes endpoint, and lodash utility usage — none of which involve eval or Function with untrusted data.
Impact: none · Exploitability: unlikely
Developer action: none
- Scanner
- opengrep 1.26.0
- Rule
- tavernkeeper.dynamic-execution.javascript-eval
- File role
- generated
- Source
- dist/index.js:45
OpenGrep reported tavernkeeper.dynamic-execution.javascript-eval
Expected behavior · high confidence
The flagged code is inside the popular Lodash utility library and uses a standard, hardcoded pattern to find the global environment. It does not process any user input and poses no security risk.
Technical evidence
Scanner reason: OpenGrep matched static-analysis rule tavernkeeper.dynamic-execution.javascript-eval in this repository.
Contextual assessment: The scanner matched a dynamic-execution pattern within the bundled Lodash library (module 543). Lodash uses Function("return this")() as a well-known, hardcoded idiom to detect the global object across environments. No user-supplied, remote, or character-card input is passed to this construct. It is a static expression evaluated once at library initialization and is not reachable as an injection vector.
Impact: none · Exploitability: unlikely
Developer action: none
- Scanner
- opengrep 1.26.0
- Rule
- tavernkeeper.dynamic-execution.javascript-eval
- File role
- generated
- Source
- dist/index.js:9