TavernKeeper Scan Report

SillyTavern/Extension-Mermaid

Commit 62265d5 Reviewed

No material or immediate-danger concern was identified in this review.

This advisory report describes what the named tools and review process found at one exact commit. Unknown or unobserved behavior may still exist.

0 immediate danger 0 material 36 low

What this review found

No material or immediate-danger item was identified.

Minor cautions

Dependency advisory GHSA-39q2-94rc-95cp applies

Minor caution · medium confidence

A library used by this extension has a known security issue. Because the extension only ships its final built file to users and not its build tools, and because the main library only processes diagram text already present in the chat, the practical risk to users is low.

Technical evidence

Scanner reason: OSV-Scanner matched advisory GHSA-39q2-94rc-95cp to a dependency declared by this repository.

Contextual assessment: A medium-severity advisory matched a dependency in the lock file. The project ships a webpack-bundled file; dev dependencies (webpack-cli, css-loader, style-loader, terser-webpack-plugin) do not reach end users. The sole production dependency is mermaid, which renders diagram syntax from chat content already controlled by the user or AI. Without specific package identification in the evidence, exact runtime reachability is uncertain, but the project structure limits concrete user harm.

Impact: low · Exploitability: unlikely

Developer action: Update the affected dependency to a patched version when convenient. If it is a build-only dependency, the update is lower priority.

Scanner
osv-scanner 2.4.0
Rule
GHSA-39q2-94rc-95cp
File role
production
Source
package-lock.json

Dependency advisory GHSA-crv5-9vww-q3g8 applies

Minor caution · medium confidence

A library used by this extension has a known security issue. Because the extension only ships its final built file to users and not its build tools, and because the main library only processes diagram text already present in the chat, the practical risk to users is low.

Technical evidence

Scanner reason: OSV-Scanner matched advisory GHSA-crv5-9vww-q3g8 to a dependency declared by this repository.

Contextual assessment: A medium-severity advisory matched a dependency in the lock file. The project ships a webpack-bundled file; dev dependencies do not reach end users. The sole production dependency is mermaid, which renders diagram syntax from chat content already controlled by the user or AI. Without specific package identification in the evidence, exact runtime reachability is uncertain, but the project structure limits concrete user harm.

Impact: low · Exploitability: unlikely

Developer action: Update the affected dependency to a patched version when convenient. If it is a build-only dependency, the update is lower priority.

Scanner
osv-scanner 2.4.0
Rule
GHSA-crv5-9vww-q3g8
File role
production
Source
package-lock.json

Dependency advisory GHSA-h7mw-gpvr-xq4m applies

Minor caution · medium confidence

A library used by this extension has a known security issue. Because the extension only ships its final built file to users and not its build tools, and because the main library only processes diagram text already present in the chat, the practical risk to users is low.

Technical evidence

Scanner reason: OSV-Scanner matched advisory GHSA-h7mw-gpvr-xq4m to a dependency declared by this repository.

Contextual assessment: A medium-severity advisory matched a dependency in the lock file. The project ships a webpack-bundled file; dev dependencies do not reach end users. The sole production dependency is mermaid, which renders diagram syntax from chat content already controlled by the user or AI. Without specific package identification in the evidence, exact runtime reachability is uncertain, but the project structure limits concrete user harm.

Impact: low · Exploitability: unlikely

Developer action: Update the affected dependency to a patched version when convenient. If it is a build-only dependency, the update is lower priority.

Scanner
osv-scanner 2.4.0
Rule
GHSA-h7mw-gpvr-xq4m
File role
production
Source
package-lock.json

Dependency advisory GHSA-cjmm-f4jc-qw8r applies

Minor caution · medium confidence

A library used by this extension has a known security issue. Because the extension only ships its final built file to users and not its build tools, and because the main library only processes diagram text already present in the chat, the practical risk to users is low.

Technical evidence

Scanner reason: OSV-Scanner matched advisory GHSA-cjmm-f4jc-qw8r to a dependency declared by this repository.

Contextual assessment: A medium-severity advisory matched a dependency in the lock file. The project ships a webpack-bundled file; dev dependencies do not reach end users. The sole production dependency is mermaid, which renders diagram syntax from chat content already controlled by the user or AI. Without specific package identification in the evidence, exact runtime reachability is uncertain, but the project structure limits concrete user harm.

Impact: low · Exploitability: unlikely

Developer action: Update the affected dependency to a patched version when convenient. If it is a build-only dependency, the update is lower priority.

Scanner
osv-scanner 2.4.0
Rule
GHSA-cjmm-f4jc-qw8r
File role
production
Source
package-lock.json

Dependency advisory GHSA-r47g-fvhr-h676 applies

Minor caution · medium confidence

A library used by this extension has a known security issue. Because the extension only ships its final built file to users and not its build tools, and because the main library only processes diagram text already present in the chat, the practical risk to users is low.

Technical evidence

Scanner reason: OSV-Scanner matched advisory GHSA-r47g-fvhr-h676 to a dependency declared by this repository.

Contextual assessment: A medium-severity advisory matched a dependency in the lock file. The project ships a webpack-bundled file; dev dependencies do not reach end users. The sole production dependency is mermaid, which renders diagram syntax from chat content already controlled by the user or AI. Without specific package identification in the evidence, exact runtime reachability is uncertain, but the project structure limits concrete user harm.

Impact: low · Exploitability: unlikely

Developer action: Update the affected dependency to a patched version when convenient. If it is a build-only dependency, the update is lower priority.

Scanner
osv-scanner 2.4.0
Rule
GHSA-r47g-fvhr-h676
File role
production
Source
package-lock.json

Dependency advisory GHSA-87f9-hvmw-gh4p applies

Minor caution · medium confidence

A library used by this extension has a known security issue. Because the extension only ships its final built file to users and not its build tools, and because the main library only processes diagram text already present in the chat, the practical risk to users is low.

Technical evidence

Scanner reason: OSV-Scanner matched advisory GHSA-87f9-hvmw-gh4p to a dependency declared by this repository.

Contextual assessment: A medium-severity advisory matched a dependency in the lock file. The project ships a webpack-bundled file; dev dependencies do not reach end users. The sole production dependency is mermaid, which renders diagram syntax from chat content already controlled by the user or AI. Without specific package identification in the evidence, exact runtime reachability is uncertain, but the project structure limits concrete user harm.

Impact: low · Exploitability: unlikely

Developer action: Update the affected dependency to a patched version when convenient. If it is a build-only dependency, the update is lower priority.

Scanner
osv-scanner 2.4.0
Rule
GHSA-87f9-hvmw-gh4p
File role
production
Source
package-lock.json

Dependency advisory GHSA-v2hh-gcrm-f6hx applies

Minor caution · medium confidence

A library used by this extension has a known security issue rated as high severity. However, because the extension only ships its final built file to users and not its build tools, and because the main library only processes diagram text already present in the chat, the practical risk to users appears low. This one deserves a closer look and a priority update.

Technical evidence

Scanner reason: OSV-Scanner matched advisory GHSA-v2hh-gcrm-f6hx to a dependency declared by this repository.

Contextual assessment: A high-severity advisory matched a dependency in the lock file. The scanner did not identify the specific package. The project ships a webpack-bundled file; dev dependencies do not reach end users. If this advisory affects a dev dependency, it has no end-user impact. If it affects a transitive dependency of mermaid, the runtime attack surface is limited to rendering user-provided mermaid syntax in chat. The higher advisory severity warrants priority attention, but without confirmed runtime reachability in the extension's usage pattern, the practical risk remains low.

Impact: medium · Exploitability: unlikely

Developer action: Identify the specific package affected by this high-severity advisory and update it to a patched version as a priority. If it is a build-only dependency, confirm it does not ship in the bundle.

Scanner
osv-scanner 2.4.0
Rule
GHSA-v2hh-gcrm-f6hx
File role
production
Source
package-lock.json

Dependency advisory GHSA-f23m-r3pf-42rh applies

Minor caution · medium confidence

A library used by this extension has a known security issue. Because the extension only ships its final built file to users and not its build tools, and because the main library only processes diagram text already present in the chat, the practical risk to users is low.

Technical evidence

Scanner reason: OSV-Scanner matched advisory GHSA-f23m-r3pf-42rh to a dependency declared by this repository.

Contextual assessment: A medium-severity advisory matched a dependency in the lock file. The project ships a webpack-bundled file; dev dependencies do not reach end users. The sole production dependency is mermaid, which renders diagram syntax from chat content already controlled by the user or AI. Without specific package identification in the evidence, exact runtime reachability is uncertain, but the project structure limits concrete user harm.

Impact: low · Exploitability: unlikely

Developer action: Update the affected dependency to a patched version when convenient. If it is a build-only dependency, the update is lower priority.

Scanner
osv-scanner 2.4.0
Rule
GHSA-f23m-r3pf-42rh
File role
production
Source
package-lock.json

Dependency advisory GHSA-v39h-62p7-jpjc applies

Minor caution · medium confidence

A security issue was found in a library used by the diagram-drawing tool this extension relies on. In theory, a specially crafted diagram could try to inject unwanted content, but the risk is low because the extension only processes diagram syntax and the chat app already handles untrusted content from AI and users.

Technical evidence

Scanner reason: OSV-Scanner matched advisory GHSA-v39h-62p7-jpjc to a dependency declared by this repository.

Contextual assessment: This advisory likely affects a runtime transitive dependency of mermaid (such as dompurify, which mermaid uses for HTML sanitization). The extension renders mermaid diagram code blocks from chat messages into SVG/HTML. A sanitization bypass in a runtime dependency could theoretically allow crafted mermaid input to inject markup into the SillyTavern page. However, SillyTavern already processes untrusted AI and user content throughout its interface, the extension's rendering surface is limited to diagram syntax, and the vulnerability is in a third-party library rather than the extension's own code. The advisory severity reflects the library-level risk, but the concrete impact in this extension context is constrained.

Impact: low · Exploitability: plausible

Developer action: Update mermaid to the latest version so its bundled sanitization dependencies incorporate upstream fixes.

Scanner
osv-scanner 2.4.0
Rule
GHSA-v39h-62p7-jpjc
File role
production
Source
package-lock.json

Dependency advisory GHSA-xcj9-5m2h-648r applies

Minor caution · medium confidence

A security issue was found in a tool used only to build the extension, not in the extension itself. Since the tool is not included in what users install, there is no risk to people using the extension.

Technical evidence

Scanner reason: OSV-Scanner matched advisory GHSA-xcj9-5m2h-648r to a dependency declared by this repository.

Contextual assessment: This medium-severity advisory most likely affects a build-time dev dependency in the webpack or loader chain (css-loader, style-loader, terser-webpack-plugin, or webpack-cli). These packages are used only during the build process to produce file and are not shipped to end users. The vulnerable code has no runtime reachability in the installed extension. No attacker-controlled input reaches these packages during normal extension operation.

Impact: none · Exploitability: unlikely

Developer action: Update dev dependencies to latest versions to keep the build environment current.

Scanner
osv-scanner 2.4.0
Rule
GHSA-xcj9-5m2h-648r
File role
production
Source
package-lock.json

Dependency advisory GHSA-ghcm-xqfw-q4vr applies

Minor caution · medium confidence

A security issue was found in a build tool that is not part of the installed extension. It does not affect users of the extension.

Technical evidence

Scanner reason: OSV-Scanner matched advisory GHSA-ghcm-xqfw-q4vr to a dependency declared by this repository.

Contextual assessment: This medium-severity advisory most likely affects a build-time dev dependency in the webpack or loader toolchain. These packages participate only in producing the compiled bundle and are not present in the shipped extension. The vulnerable code paths are not reachable at runtime, and no user-controlled input flows to these packages during extension operation.

Impact: none · Exploitability: unlikely

Developer action: Update dev dependencies to latest versions to keep the build environment current.

Scanner
osv-scanner 2.4.0
Rule
GHSA-ghcm-xqfw-q4vr
File role
production
Source
package-lock.json

Dependency advisory GHSA-76mc-f452-cxcm applies

Minor caution · medium confidence

A security issue was found in a build-related package that does not ship with the extension. It poses no risk to extension users.

Technical evidence

Scanner reason: OSV-Scanner matched advisory GHSA-76mc-f452-cxcm to a dependency declared by this repository.

Contextual assessment: This medium-severity advisory most likely affects a dev or build-time transitive dependency. The extension's only runtime dependency is mermaid, while the remaining declared dependencies are webpack build tools. Build-time packages are not included in the production bundle and have no runtime reachability. No attacker-controlled input reaches these packages during extension use.

Impact: none · Exploitability: unlikely

Developer action: Update dev dependencies to latest versions to keep the build environment current.

Scanner
osv-scanner 2.4.0
Rule
GHSA-76mc-f452-cxcm
File role
production
Source
package-lock.json

Dependency advisory GHSA-q3j6-qgpj-74h6 applies

Minor caution · medium confidence

A security issue was found in a library that helps the extension draw diagrams. A carefully crafted diagram might try to inject unwanted content, but the risk is low because the extension only handles diagram code and the chat app already manages untrusted content.

Technical evidence

Scanner reason: OSV-Scanner matched advisory GHSA-q3j6-qgpj-74h6 to a dependency declared by this repository.

Contextual assessment: This high-severity advisory likely affects a runtime transitive dependency of mermaid, such as dompurify or another library in mermaid's rendering pipeline. The extension processes mermaid syntax from chat messages and renders it to SVG or HTML. A sanitization or parsing bypass in a runtime dependency could allow a crafted diagram to inject content into the page. However, the attack surface is limited to mermaid diagram syntax, SillyTavern already handles untrusted content throughout its interface, and the vulnerability resides in a third-party library rather than the extension's own logic. The concrete user harm in this context is bounded.

Impact: low · Exploitability: plausible

Developer action: Update mermaid to the latest version so its bundled dependencies incorporate upstream security fixes.

Scanner
osv-scanner 2.4.0
Rule
GHSA-q3j6-qgpj-74h6
File role
production
Source
package-lock.json

Dependency advisory GHSA-7p8r-x3mc-p8w7 applies

Minor caution · medium confidence

A security issue was found in a library used by the diagram tool. While a specially crafted diagram could theoretically cause problems, the actual risk is low because the extension only processes diagram syntax and the chat app already handles untrusted content.

Technical evidence

Scanner reason: OSV-Scanner matched advisory GHSA-7p8r-x3mc-p8w7 to a dependency declared by this repository.

Contextual assessment: This high-severity advisory likely affects a runtime transitive dependency of mermaid. The extension renders mermaid code blocks from chat content into visual diagrams. If the advisory targets a sanitization or parsing library in mermaid's dependency tree, a crafted diagram could potentially bypass protections and inject markup. The impact is constrained because the extension processes only diagram syntax, SillyTavern already manages untrusted AI and user content across its interface, and the issue is in a third-party dependency rather than the extension's own code.

Impact: low · Exploitability: plausible

Developer action: Update mermaid to the latest version so its bundled dependencies incorporate upstream security fixes.

Scanner
osv-scanner 2.4.0
Rule
GHSA-7p8r-x3mc-p8w7
File role
production
Source
package-lock.json

Dependency advisory GHSA-c2j3-45gr-mqc4 applies

Minor caution · medium confidence

A minor security issue was found in a dependency. The risk is very low and does not meaningfully affect extension users.

Technical evidence

Scanner reason: OSV-Scanner matched advisory GHSA-c2j3-45gr-mqc4 to a dependency declared by this repository.

Contextual assessment: This low-severity advisory affects a dependency in the project's lockfile. Given the low severity and the project's dependency structure (mermaid as the sole runtime dependency, webpack toolchain as dev dependencies), the vulnerable code is either in a build-time package with no runtime reachability or in a runtime dependency with a minor issue that has negligible practical impact in this extension's diagram-rendering context.

Impact: none · Exploitability: unlikely

Developer action: Update dependencies to latest versions when convenient.

Scanner
osv-scanner 2.4.0
Rule
GHSA-c2j3-45gr-mqc4
File role
production
Source
package-lock.json

Dependency advisory GHSA-6g55-p6wh-862q applies

Minor caution · medium confidence

A security issue was found in a library used by the diagram-drawing tool. A specially crafted diagram could theoretically cause issues, but the risk is low because the extension only handles diagram code and the chat app already manages untrusted content.

Technical evidence

Scanner reason: OSV-Scanner matched advisory GHSA-6g55-p6wh-862q to a dependency declared by this repository.

Contextual assessment: This high-severity advisory likely affects a runtime transitive dependency of mermaid, such as a sanitization or parsing library. The extension renders mermaid diagram syntax from chat messages into SVG or HTML output. A bypass in a runtime dependency could allow a crafted diagram to inject content into the SillyTavern page. The practical impact is limited because the extension only processes diagram syntax, SillyTavern already handles untrusted content throughout its interface, and the vulnerability is in a third-party library rather than the extension's own code.

Impact: low · Exploitability: plausible

Developer action: Update mermaid to the latest version so its bundled dependencies incorporate upstream security fixes.

Scanner
osv-scanner 2.4.0
Rule
GHSA-6g55-p6wh-862q
File role
production
Source
package-lock.json

Dependency advisory GHSA-6m6c-36f7-fhxh applies

Minor caution · medium confidence

A dependency used by this extension has a known security issue. However, this extension ships a bundled file to users, and the vulnerable dependency is most likely part of the build toolchain that only runs on the developer's machine, not on the user's. The risk to people who install and use this extension is low.

Technical evidence

Scanner reason: OSV-Scanner matched advisory GHSA-6m6c-36f7-fhxh to a dependency declared by this repository.

Contextual assessment: This advisory matches a dependency declared in the lockfile of a SillyTavern browser extension whose sole runtime dependency is mermaid ^11.12.3. The devDependencies (css-loader, style-loader, terser-webpack-plugin, webpack-cli) and their transitive trees are build-time only and do not ship in the bundled dist/index.js. Without the specific package name, the most probable mapping for a medium-severity advisory in this lockfile is a build-tool transitive dependency such as tar or a webpack-related package. Such vulnerabilities require attacker-controlled input during the build process, which is unlikely. The shipped artifact is a browser bundle, limiting the attack surface for server-side or filesystem-oriented advisory types.

Impact: low · Exploitability: unlikely

Developer action: Update affected dependency when a patched version is available. If this is a build-tool transitive dependency, the urgency is low since it does not ship to end users.

Scanner
osv-scanner 2.4.0
Rule
GHSA-6m6c-36f7-fhxh
File role
production
Source
package-lock.json

Dependency advisory GHSA-r5fr-rjxr-66jc applies

Minor caution · medium confidence

A dependency used by this extension has a known security issue rated high severity. However, this extension ships a bundled file to users, and the vulnerable dependency is most likely part of the build toolchain that only runs on the developer's machine. The risk to people who install and use this extension is low.

Technical evidence

Scanner reason: OSV-Scanner matched advisory GHSA-r5fr-rjxr-66jc to a dependency declared by this repository.

Contextual assessment: This high-severity advisory matches a dependency in the lockfile. The project ships a webpack-bundled file to end users; devDependencies and their transitive trees do not ship. High-severity advisories in build-tool transitive dependencies (e.g., tar path traversal, webpack-dev-middleware issues) require attacker-controlled build inputs to exploit, which is unlikely in this extension's build pipeline. The runtime dependency mermaid 11.12.3 is recent. Without the specific package identifier, the most probable mapping is a build-tool transitive dependency, making end-user impact low.

Impact: low · Exploitability: unlikely

Developer action: Update affected dependency when a patched version is available. If this is a build-tool transitive dependency, the urgency is low since it does not ship to end users.

Scanner
osv-scanner 2.4.0
Rule
GHSA-r5fr-rjxr-66jc
File role
production
Source
package-lock.json

Dependency advisory GHSA-r28c-9q8g-f849 applies

Minor caution · medium confidence

A dependency used by this extension has a known security issue rated high severity. However, this extension ships a bundled file to users, and the vulnerable dependency is most likely part of the build toolchain that only runs on the developer's machine. The risk to people who install and use this extension is low.

Technical evidence

Scanner reason: OSV-Scanner matched advisory GHSA-r28c-9q8g-f849 to a dependency declared by this repository.

Contextual assessment: This high-severity advisory matches a dependency in the lockfile. The project ships a webpack-bundled file to end users; devDependencies and their transitive trees do not ship. High-severity advisories in build-tool transitive dependencies require attacker-controlled build inputs to exploit, which is unlikely in this extension's build pipeline. The runtime dependency mermaid 11.12.3 is recent. Without the specific package identifier, the most probable mapping is a build-tool transitive dependency, making end-user impact low.

Impact: low · Exploitability: unlikely

Developer action: Update affected dependency when a patched version is available. If this is a build-tool transitive dependency, the urgency is low since it does not ship to end users.

Scanner
osv-scanner 2.4.0
Rule
GHSA-r28c-9q8g-f849
File role
production
Source
package-lock.json

Dependency advisory GHSA-4c8g-83qw-93j6 applies

Minor caution · medium confidence

A dependency used by this extension has a known security issue rated high severity. However, this extension ships a bundled file to users, and the vulnerable dependency is most likely part of the build toolchain that only runs on the developer's machine. The risk to people who install and use this extension is low.

Technical evidence

Scanner reason: OSV-Scanner matched advisory GHSA-4c8g-83qw-93j6 to a dependency declared by this repository.

Contextual assessment: This high-severity advisory matches a dependency in the lockfile. The project ships a webpack-bundled file to end users; devDependencies and their transitive trees do not ship. High-severity advisories in build-tool transitive dependencies require attacker-controlled build inputs to exploit, which is unlikely in this extension's build pipeline. The runtime dependency mermaid 11.12.3 is recent. Without the specific package identifier, the most probable mapping is a build-tool transitive dependency, making end-user impact low.

Impact: low · Exploitability: unlikely

Developer action: Update affected dependency when a patched version is available. If this is a build-tool transitive dependency, the urgency is low since it does not ship to end users.

Scanner
osv-scanner 2.4.0
Rule
GHSA-4c8g-83qw-93j6
File role
production
Source
package-lock.json

Dependency advisory GHSA-cj63-jhhr-wcxv applies

Minor caution · medium confidence

A dependency used by this extension has a known security issue. However, this extension ships a bundled file to users, and the vulnerable dependency is most likely part of the build toolchain that only runs on the developer's machine, not on the user's. The risk to people who install and use this extension is low.

Technical evidence

Scanner reason: OSV-Scanner matched advisory GHSA-cj63-jhhr-wcxv to a dependency declared by this repository.

Contextual assessment: This medium-severity advisory matches a dependency in the lockfile. The project ships a webpack-bundled file to end users; devDependencies and their transitive trees do not ship. Medium-severity advisories in build-tool transitive dependencies require attacker-controlled build inputs to exploit, which is unlikely. The runtime dependency mermaid 11.12.3 is recent. Without the specific package identifier, the most probable mapping is a build-tool transitive dependency, making end-user impact low.

Impact: low · Exploitability: unlikely

Developer action: Update affected dependency when a patched version is available. If this is a build-tool transitive dependency, the urgency is low since it does not ship to end users.

Scanner
osv-scanner 2.4.0
Rule
GHSA-cj63-jhhr-wcxv
File role
production
Source
package-lock.json

Dependency advisory GHSA-w5hq-g745-h8pq applies

Minor caution · medium confidence

A dependency used by this extension has a known security issue. However, this extension ships a bundled file to users, and the vulnerable dependency is most likely part of the build toolchain that only runs on the developer's machine, not on the user's. The risk to people who install and use this extension is low.

Technical evidence

Scanner reason: OSV-Scanner matched advisory GHSA-w5hq-g745-h8pq to a dependency declared by this repository.

Contextual assessment: This medium-severity advisory matches a dependency in the lockfile. The project ships a webpack-bundled file to end users; devDependencies and their transitive trees do not ship. Medium-severity advisories in build-tool transitive dependencies require attacker-controlled build inputs to exploit, which is unlikely. The runtime dependency mermaid 11.12.3 is recent. Without the specific package identifier, the most probable mapping is a build-tool transitive dependency, making end-user impact low.

Impact: low · Exploitability: unlikely

Developer action: Update affected dependency when a patched version is available. If this is a build-tool transitive dependency, the urgency is low since it does not ship to end users.

Scanner
osv-scanner 2.4.0
Rule
GHSA-w5hq-g745-h8pq
File role
production
Source
package-lock.json

Dependency advisory GHSA-h8r8-wccr-v5f2 applies

Minor caution · medium confidence

A dependency used by this extension has a known security issue. However, this extension ships a bundled file to users, and the vulnerable dependency is most likely part of the build toolchain that only runs on the developer's machine, not on the user's. The risk to people who install and use this extension is low.

Technical evidence

Scanner reason: OSV-Scanner matched advisory GHSA-h8r8-wccr-v5f2 to a dependency declared by this repository.

Contextual assessment: This medium-severity advisory matches a dependency in the lockfile. The project ships a webpack-bundled file to end users; devDependencies and their transitive trees do not ship. Medium-severity advisories in build-tool transitive dependencies require attacker-controlled build inputs to exploit, which is unlikely. The runtime dependency mermaid 11.12.3 is recent. Without the specific package identifier, the most probable mapping is a build-tool transitive dependency, making end-user impact low.

Impact: low · Exploitability: unlikely

Developer action: Update affected dependency when a patched version is available. If this is a build-tool transitive dependency, the urgency is low since it does not ship to end users.

Scanner
osv-scanner 2.4.0
Rule
GHSA-h8r8-wccr-v5f2
File role
production
Source
package-lock.json

Dependency advisory GHSA-v9jr-rg53-9pgp applies

Minor caution · medium confidence

A dependency used by this extension has a known security issue. However, this extension ships a bundled file to users, and the vulnerable dependency is most likely part of the build toolchain that only runs on the developer's machine, not on the user's. The risk to people who install and use this extension is low.

Technical evidence

Scanner reason: OSV-Scanner matched advisory GHSA-v9jr-rg53-9pgp to a dependency declared by this repository.

Contextual assessment: This medium-severity advisory matches a dependency in the lockfile. The project ships a webpack-bundled file to end users; devDependencies and their transitive trees do not ship. Medium-severity advisories in build-tool transitive dependencies require attacker-controlled build inputs to exploit, which is unlikely. The runtime dependency mermaid 11.12.3 is recent. Without the specific package identifier, the most probable mapping is a build-tool transitive dependency, making end-user impact low.

Impact: low · Exploitability: unlikely

Developer action: Update affected dependency when a patched version is available. If this is a build-tool transitive dependency, the urgency is low since it does not ship to end users.

Scanner
osv-scanner 2.4.0
Rule
GHSA-v9jr-rg53-9pgp
File role
production
Source
package-lock.json

Dependency advisory GHSA-rp9w-3fw7-7cwq applies

Minor caution · medium confidence

This is a security issue in a tool used to compile the extension, not in the extension that users run. It does not expose people who install and use the extension.

Technical evidence

Scanner reason: OSV-Scanner matched advisory GHSA-rp9w-3fw7-7cwq to a dependency declared by this repository.

Contextual assessment: The advisory matches a known issue in build or development tooling rather than the mermaid runtime. The extension ships a prebuilt bundle referenced by its manifest; vulnerable code in build-time dependencies is not loaded or executed when SillyTavern renders diagrams. Exploitation would require a local build or development-server context, not user-supplied diagram input.

Impact: low · Exploitability: unlikely

Developer action: Update the affected build or development dependency to a fixed version when convenient; no runtime impact for end users.

Scanner
osv-scanner 2.4.0
Rule
GHSA-rp9w-3fw7-7cwq
File role
production
Source
package-lock.json

Dependency advisory GHSA-qx2v-qp2m-jg93 applies

Minor caution · medium confidence

This vulnerability affects software used to create the extension, not the extension itself. Users are not exposed during normal use.

Technical evidence

Scanner reason: OSV-Scanner matched advisory GHSA-qx2v-qp2m-jg93 to a dependency declared by this repository.

Contextual assessment: The advisory corresponds to a dependency used for building or serving during development. The shipped extension artifact is a compiled bundle, and the vulnerable code path is not present in the runtime that SillyTavern loads. Attacker control would need to reach the build or local dev environment, not the extension's diagram rendering.

Impact: low · Exploitability: unlikely

Developer action: Update the affected build or development dependency to a fixed version when convenient; no runtime impact for end users.

Scanner
osv-scanner 2.4.0
Rule
GHSA-qx2v-qp2m-jg93
File role
production
Source
package-lock.json

Dependency advisory GHSA-cmwh-pvxp-8882 applies

Minor caution · medium confidence

The issue is in a compiler or development tool, not in the finished extension. It does not affect users who install and run the extension.

Technical evidence

Scanner reason: OSV-Scanner matched advisory GHSA-cmwh-pvxp-8882 to a dependency declared by this repository.

Contextual assessment: This advisory is associated with build or development tooling, not the mermaid library that the extension uses at runtime. The extension distributes a prebuilt bundle, so the vulnerable code is not executed when users render diagrams. Exploitation would require access to the build pipeline or local development server.

Impact: low · Exploitability: unlikely

Developer action: Update the affected build or development dependency to a fixed version when convenient; no runtime impact for end users.

Scanner
osv-scanner 2.4.0
Rule
GHSA-cmwh-pvxp-8882
File role
production
Source
package-lock.json

Dependency advisory GHSA-fxqj-rqcc-2cmp applies

Minor caution · medium confidence

This is a security flaw in a tool used during development, not in the extension that users run. Normal use is not affected.

Technical evidence

Scanner reason: OSV-Scanner matched advisory GHSA-fxqj-rqcc-2cmp to a dependency declared by this repository.

Contextual assessment: The advisory relates to a development or build-time dependency. The runtime extension is a compiled bundle loaded by SillyTavern, and the vulnerable code is not part of that runtime. User-controlled mermaid diagram input does not reach the vulnerable component.

Impact: low · Exploitability: unlikely

Developer action: Update the affected build or development dependency to a fixed version when convenient; no runtime impact for end users.

Scanner
osv-scanner 2.4.0
Rule
GHSA-fxqj-rqcc-2cmp
File role
production
Source
package-lock.json

Dependency advisory GHSA-gvmj-g25r-r7wr applies

Minor caution · medium confidence

This is a minor issue in a development tool, not in the extension itself. Users are not exposed during normal use.

Technical evidence

Scanner reason: OSV-Scanner matched advisory GHSA-gvmj-g25r-r7wr to a dependency declared by this repository.

Contextual assessment: The low-severity advisory matches a build or development dependency. The extension's shipped artifact is a prebuilt bundle, and the vulnerable code is not executed during diagram rendering. Exploitation would require a local build or development context rather than user input.

Impact: low · Exploitability: unlikely

Developer action: Update the affected build or development dependency to a fixed version when convenient; no runtime impact for end users.

Scanner
osv-scanner 2.4.0
Rule
GHSA-gvmj-g25r-r7wr
File role
production
Source
package-lock.json

Dependency advisory GHSA-v2wj-7wpq-c8vv applies

Minor caution · medium confidence

This vulnerability affects software used to build the extension, not the extension that users run. It does not expose users during normal use.

Technical evidence

Scanner reason: OSV-Scanner matched advisory GHSA-v2wj-7wpq-c8vv to a dependency declared by this repository.

Contextual assessment: The advisory corresponds to a dependency in the build or development toolchain. The runtime extension is a compiled bundle, and the vulnerable code path is not present in the SillyTavern-loaded artifact. Attacker control would need to reach the build or local dev environment.

Impact: low · Exploitability: unlikely

Developer action: Update the affected build or development dependency to a fixed version when convenient; no runtime impact for end users.

Scanner
osv-scanner 2.4.0
Rule
GHSA-v2wj-7wpq-c8vv
File role
production
Source
package-lock.json

Dependency advisory GHSA-x4vx-rjvf-j5p4 applies

Minor caution · medium confidence

This is a minor issue in a development tool, not in the finished extension. Users are not affected during normal use.

Technical evidence

Scanner reason: OSV-Scanner matched advisory GHSA-x4vx-rjvf-j5p4 to a dependency declared by this repository.

Contextual assessment: The low-severity advisory is associated with build or development tooling. The extension ships a prebuilt bundle, and the vulnerable code is not loaded when SillyTavern renders mermaid diagrams. Exploitation would require a local build or development context, not user-supplied input.

Impact: low · Exploitability: unlikely

Developer action: Update the affected build or development dependency to a fixed version when convenient; no runtime impact for end users.

Scanner
osv-scanner 2.4.0
Rule
GHSA-x4vx-rjvf-j5p4
File role
production
Source
package-lock.json

Dependency advisory GHSA-hpcv-96wg-7vj8 applies

Minor caution · medium confidence

This is a security issue in a tool used to create the extension, not in the extension itself. It does not expose users during normal use.

Technical evidence

Scanner reason: OSV-Scanner matched advisory GHSA-hpcv-96wg-7vj8 to a dependency declared by this repository.

Contextual assessment: The advisory matches a known issue in build or development tooling. The runtime extension is a compiled bundle, and the vulnerable component is not executed during diagram rendering. User-controlled mermaid input does not reach the vulnerable code path.

Impact: low · Exploitability: unlikely

Developer action: Update the affected build or development dependency to a fixed version when convenient; no runtime impact for end users.

Scanner
osv-scanner 2.4.0
Rule
GHSA-hpcv-96wg-7vj8
File role
production
Source
package-lock.json

Dependency advisory GHSA-vxr8-fq34-vvx9 applies

Minor caution · low confidence

A minor known issue was found in a supporting library used by the diagram-drawing tool. Because this extension only draws diagrams from chat text and does not handle passwords or sensitive data, the practical risk is very low.

Technical evidence

Scanner reason: OSV-Scanner matched advisory GHSA-vxr8-fq34-vvx9 to a dependency declared by this repository.

Contextual assessment: A low-severity advisory was matched against a transitive dependency declared in the lockfile for this Mermaid-rendering extension. The extension's runtime surface is narrow: it parses mermaid code blocks from chat messages and renders diagrams client-side. It does not handle credentials, API keys, or sensitive host state. The advisory severity is low and the vulnerable code path is unlikely to be reachable with attacker-controlled input that produces concrete user harm in this extension's usage context.

Impact: low · Exploitability: unlikely

Developer action: Update the affected dependency to a patched version when a compatible release is available, as routine maintenance.

Scanner
osv-scanner 2.4.0
Rule
GHSA-vxr8-fq34-vvx9
File role
production
Source
package-lock.json

Dependency advisory GHSA-v8jm-5vwx-cfxm applies

Minor caution · low confidence

A known issue of moderate severity was found in a library used by the diagram tool. Since the tool only draws diagrams from chat text and does not touch sensitive data, the real-world risk remains low, though it is worth addressing in a routine update.

Technical evidence

Scanner reason: OSV-Scanner matched advisory GHSA-v8jm-5vwx-cfxm to a dependency declared by this repository.

Contextual assessment: A medium-severity advisory was matched against a transitive dependency in the lockfile. The extension renders mermaid diagram syntax from chat messages, so attacker-controlled input can reach the rendering pipeline. However, the extension processes only diagram markup, does not access model-provider credentials, does not intercept generations, and does not persist sensitive data. The medium advisory severity does not by itself indicate concrete user harm in this narrow rendering context, and the actual impact is bounded to the client-side diagram rendering surface.

Impact: low · Exploitability: plausible

Developer action: Update the affected dependency to a patched version when a compatible release is available, and verify that mermaid code-block input is sanitized per the library's recommendations.

Scanner
osv-scanner 2.4.0
Rule
GHSA-v8jm-5vwx-cfxm
File role
production
Source
package-lock.json
Expected scanner matches (1)

OpenGrep reported tavernkeeper.dynamic-execution.javascript-eval

Expected behavior · high confidence

The flagged code belongs to DOMPurify, a standard security library that cleans unsafe HTML. The pattern that triggered the scan is the library's internal protective code that safely calls built-in browser functions. No untrusted input is executed as code here. This is normal and expected for a diagram extension that needs to sanitize its output.

Technical evidence

Scanner reason: OpenGrep matched static-analysis rule tavernkeeper.dynamic-execution.javascript-eval in this repository.

Contextual assessment: The matched line is the opening of the bundled DOMPurify 3.2.6 library, explicitly identified by the license comment on the preceding line. The dynamic execution pattern detected is DOMPurify's hardening wrapper around native prototype methods. It creates safe aliases for apply and construct, falling back to Function.prototype.apply and new when Reflect is unavailable. The helper M resets regex lastIndex and invokes methods via apply on hardcoded native prototype references, which is a defensive measure against prototype tampering of the sanitizer itself. No user-controlled strings are passed to eval, Function, or new Function. This code is invoked internally during sanitization of Mermaid rendered output and aligns with the project's stated purpose.

Impact: none · Exploitability: unlikely

Developer action: none

Scanner
opengrep 1.26.0
Rule
tavernkeeper.dynamic-execution.javascript-eval
File role
generated
Source
dist/index.js:3

Related contextual observations

Advisory package identities are redacted, limiting precise runtime versus build-time classification

low risk · medium confidence

The scanner flagged eight dependency advisories but removed the package names, making it impossible to confirm whether each vulnerable package is part of the build toolchain or the runtime library that ships to users. The most likely scenario is that these are build-tool dependencies that do not reach end users, but this cannot be fully confirmed from the supplied evidence.

Technical assessment

All eight advisories have package details removed by the scanner, preventing definitive mapping to runtime versus build-only dependencies. The lockfile shows one runtime dependency (mermaid ^11.12.3) and four devDependencies (css-loader, style-loader, terser-webpack-plugin, webpack-cli). The webpack ecosystem has large transitive trees that commonly trigger advisories for packages like tar, webpack-dev-middleware, and similar build-time tools. These do not ship in the bundled dist/index.js. However, if any advisory maps to a mermaid runtime transitive dependency with an XSS or sanitization bypass (e.g., dompurify or sanitize-url), the risk could be higher because mermaid renders user-supplied diagram code in the browser. The partial lockfile excerpt confirms @braintree/sanitize-url 7.1.2 is present as a mermaid transitive dependency. Developers should verify each advisory's specific package to distinguish build-only from runtime impact.

Impact: low · Exploitability: unlikely

Developer action: Run npm audit or osv-scanner with package details visible to identify which advisories map to runtime versus build-only dependencies. Prioritize updating any runtime transitive dependency of mermaid that has a known XSS or sanitization bypass advisory.

Sources:

Coverage and limitations

Tools

Limitations

Technical scan identity