What this review found
Dependency advisory GHSA-v6h2-p8h4-qcjw applies
Material concern · low confidence
A scanner found a known issue in one dependency, but the supplied evidence does not say which package or whether the extension uses the affected code.
Technical evidence
Scanner reason: OSV-Scanner matched advisory GHSA-v6h2-p8h4-qcjw to a dependency declared by this repository.
Contextual assessment: The advisory match is present in the production lockfile, but package identity, installed version, vulnerable component, reachability, attacker-controlled input, and concrete impact are omitted. The finding therefore cannot be reduced to a low-risk conclusion from the supplied context.
Impact: medium · Exploitability: plausible
Developer action: Identify the affected package and installed version, confirm runtime reachability, then update to a fixed version if applicable.
- Scanner
- osv-scanner 2.4.0
- Rule
- GHSA-v6h2-p8h4-qcjw
- File role
- production
- Source
- package-lock.json
Dependency advisory GHSA-4x5r-pxfx-6jf8 applies
Material concern · low confidence
A scanner found a known issue in one dependency, but the available report does not show whether it affects the extension during normal use.
Technical evidence
Scanner reason: OSV-Scanner matched advisory GHSA-4x5r-pxfx-6jf8 to a dependency declared by this repository.
Contextual assessment: The advisory match is reported for the shipped lockfile, while package/version and runtime data were removed. Exploitability and impact cannot be determined without mapping the advisory to the resolved dependency and execution path.
Impact: medium · Exploitability: plausible
Developer action: Identify the affected package and installed version, confirm runtime reachability, then update to a fixed version if applicable.
- Scanner
- osv-scanner 2.4.0
- Rule
- GHSA-4x5r-pxfx-6jf8
- File role
- production
- Source
- package-lock.json
Dependency advisory GHSA-fv7c-fp4j-7gwp applies
Material concern · low confidence
A high-severity advisory was detected, but the evidence does not reveal what library is affected or whether users can reach the vulnerable behavior.
Technical evidence
Scanner reason: OSV-Scanner matched advisory GHSA-fv7c-fp4j-7gwp to a dependency declared by this repository.
Contextual assessment: The scanner reports a high-severity advisory in the production lockfile, but omits package identity, resolved version, vulnerable function, reachability, and input control. High scanner severity alone does not establish immediate danger.
Impact: high · Exploitability: plausible
Developer action: Identify the affected package and installed version, assess runtime reachability and attacker-controlled inputs, and update to a fixed version if applicable.
- Scanner
- osv-scanner 2.4.0
- Rule
- GHSA-fv7c-fp4j-7gwp
- File role
- production
- Source
- package-lock.json
Dependency advisory GHSA-mh29-5h37-fv8m applies
Material concern · low confidence
A scanner reported a medium-severity dependency problem, but more information is needed to know whether it can affect extension users.
Technical evidence
Scanner reason: OSV-Scanner matched advisory GHSA-mh29-5h37-fv8m to a dependency declared by this repository.
Contextual assessment: The lockfile contains an advisory match, but the affected dependency, version, reachability, and concrete harm are not supplied. This supports remediation and investigation, not a definitive exploitability conclusion.
Impact: medium · Exploitability: plausible
Developer action: Identify the affected package and installed version, determine whether the vulnerable path is reachable, and update to a fixed version if applicable.
- Scanner
- osv-scanner 2.4.0
- Rule
- GHSA-mh29-5h37-fv8m
- File role
- production
- Source
- package-lock.json
Dependency advisory GHSA-qj8w-gfj5-8c6v applies
Material concern · low confidence
A scanner reported a dependency issue, but the supplied evidence does not show whether normal Roadway use triggers it.
Technical evidence
Scanner reason: OSV-Scanner matched advisory GHSA-qj8w-gfj5-8c6v to a dependency declared by this repository.
Contextual assessment: The advisory is associated with the shipped lockfile, while the dependency name, version, vulnerable code path, and attacker-control conditions are absent. Contextual assessment remains material pending those details.
Impact: medium · Exploitability: plausible
Developer action: Identify the affected package and installed version, determine whether the vulnerable path is reachable, and update to a fixed version if applicable.
- Scanner
- osv-scanner 2.4.0
- Rule
- GHSA-qj8w-gfj5-8c6v
- File role
- production
- Source
- package-lock.json
Dependency advisory GHSA-5c6j-r48x-rmvq applies
Material concern · low confidence
A high-severity dependency advisory was found, but the report does not provide enough detail to tell whether users face that risk in this extension.
Technical evidence
Scanner reason: OSV-Scanner matched advisory GHSA-5c6j-r48x-rmvq to a dependency declared by this repository.
Contextual assessment: The scanner identifies a high-severity advisory but withholds package and version details and supplies no runtime reachability or exploit preconditions. Immediate high risk is not established, but remediation should be investigated.
Impact: high · Exploitability: plausible
Developer action: Identify the affected package and installed version, assess reachability and input control, and update to a fixed version if applicable.
- Scanner
- osv-scanner 2.4.0
- Rule
- GHSA-5c6j-r48x-rmvq
- File role
- production
- Source
- package-lock.json
Dependency advisory GHSA-v2hh-gcrm-f6hx applies
Material concern · low confidence
A high-severity library issue was detected, but the evidence does not show which library is involved or whether Roadway can invoke the vulnerable behavior.
Technical evidence
Scanner reason: OSV-Scanner matched advisory GHSA-v2hh-gcrm-f6hx to a dependency declared by this repository.
Contextual assessment: The lockfile advisory match lacks the package, resolved version, vulnerable operation, reachability, and attacker-control analysis required to establish immediate danger. Treat as a remediation candidate pending dependency mapping.
Impact: high · Exploitability: plausible
Developer action: Identify the affected package and installed version, assess reachability and input control, and update to a fixed version if applicable.
- Scanner
- osv-scanner 2.4.0
- Rule
- GHSA-v2hh-gcrm-f6hx
- File role
- production
- Source
- package-lock.json
Dependency advisory GHSA-968p-4wvh-cqc8 applies
Material concern · low confidence
A scanner found a medium-severity issue in a dependency, but the supplied report does not show whether it affects users of the extension.
Technical evidence
Scanner reason: OSV-Scanner matched advisory GHSA-968p-4wvh-cqc8 to a dependency declared by this repository.
Contextual assessment: The advisory is reported against the shipped lockfile, but package identity, resolved version, runtime use, and exploit conditions are unavailable. A low-risk conclusion would be unsupported.
Impact: medium · Exploitability: plausible
Developer action: Identify the affected package and installed version, confirm runtime reachability, and update to a fixed version if applicable.
- Scanner
- osv-scanner 2.4.0
- Rule
- GHSA-968p-4wvh-cqc8
- File role
- production
- Source
- package-lock.json
Dependency advisory GHSA-2g4f-4pwh-qvx6 applies
Material concern · low confidence
A dependency was matched to a published security advisory, but the supplied evidence does not identify the package, version, or whether the vulnerable feature is used.
Technical evidence
Scanner reason: OSV-Scanner matched advisory GHSA-2g4f-4pwh-qvx6 to a dependency declared by this repository.
Contextual assessment: The scanner reports an advisory match in the production lockfile, but package details, installed version, vulnerable code path, attacker-controlled input, and runtime reachability are absent. The finding cannot be reduced to a confirmed runtime issue from this evidence alone.
Impact: medium · Exploitability: plausible
Developer action: Identify the affected package and installed version, confirm runtime reachability and advisory conditions, then update or pin a fixed version if applicable.
- Scanner
- osv-scanner 2.4.0
- Rule
- GHSA-2g4f-4pwh-qvx6
- File role
- production
- Source
- package-lock.json
Dependency advisory GHSA-v39h-62p7-jpjc applies
Material concern · low confidence
A dependency was matched to a high-severity security advisory, but the supplied evidence does not show which package is involved or whether users can trigger the vulnerable behavior.
Technical evidence
Scanner reason: OSV-Scanner matched advisory GHSA-v39h-62p7-jpjc to a dependency declared by this repository.
Contextual assessment: The scanner reports a high-severity advisory match in the production lockfile, but omits package identity, installed version, reachability, input control, and concrete impact. Severity alone does not establish an immediately exploitable runtime vulnerability.
Impact: high · Exploitability: plausible
Developer action: Identify the affected package and installed version, confirm runtime reachability and advisory conditions, then update or pin a fixed version if applicable.
- Scanner
- osv-scanner 2.4.0
- Rule
- GHSA-v39h-62p7-jpjc
- File role
- production
- Source
- package-lock.json
Dependency advisory GHSA-h67p-54hq-rp68 applies
Material concern · low confidence
A dependency was matched to a published security advisory, but there is not enough information to tell whether the vulnerable part is used by the extension.
Technical evidence
Scanner reason: OSV-Scanner matched advisory GHSA-h67p-54hq-rp68 to a dependency declared by this repository.
Contextual assessment: The scanner reports an advisory match, while the supplied context lacks package/version mapping, vulnerable range, runtime reachability, attacker-controlled input, and resulting harm.
Impact: medium · Exploitability: plausible
Developer action: Identify the affected package and installed version, confirm runtime reachability and advisory conditions, then update or pin a fixed version if applicable.
- Scanner
- osv-scanner 2.4.0
- Rule
- GHSA-h67p-54hq-rp68
- File role
- production
- Source
- package-lock.json
Dependency advisory GHSA-q3j6-qgpj-74h6 applies
Material concern · low confidence
A dependency was matched to a high-severity security advisory, but the evidence does not establish that the extension reaches the affected code.
Technical evidence
Scanner reason: OSV-Scanner matched advisory GHSA-q3j6-qgpj-74h6 to a dependency declared by this repository.
Contextual assessment: The finding is limited to a high-severity advisory identifier associated with a lockfile dependency. Package identity, version, runtime use, attacker input, and exploit conditions were removed.
Impact: high · Exploitability: plausible
Developer action: Identify the affected package and installed version, confirm runtime reachability and advisory conditions, then update or pin a fixed version if applicable.
- Scanner
- osv-scanner 2.4.0
- Rule
- GHSA-q3j6-qgpj-74h6
- File role
- production
- Source
- package-lock.json
Dependency advisory GHSA-wf6x-7x77-mvgw applies
Material concern · low confidence
A dependency was matched to a high-severity security advisory, but the supplied evidence does not show whether this affects the shipped extension.
Technical evidence
Scanner reason: OSV-Scanner matched advisory GHSA-wf6x-7x77-mvgw to a dependency declared by this repository.
Contextual assessment: The scanner reports a high-severity advisory match, but does not provide the affected package, installed version, reachable feature, attacker-controlled input, or concrete impact.
Impact: high · Exploitability: plausible
Developer action: Identify the affected package and installed version, confirm runtime reachability and advisory conditions, then update or pin a fixed version if applicable.
- Scanner
- osv-scanner 2.4.0
- Rule
- GHSA-wf6x-7x77-mvgw
- File role
- production
- Source
- package-lock.json
Dependency advisory GHSA-23c5-xmqv-rm74 applies
Material concern · low confidence
A dependency was matched to a high-severity security advisory, but the evidence is insufficient to determine whether it can affect users of this extension.
Technical evidence
Scanner reason: OSV-Scanner matched advisory GHSA-23c5-xmqv-rm74 to a dependency declared by this repository.
Contextual assessment: Only the advisory match and scanner severity are supplied. The package/version, affected code path, runtime reachability, attacker control, and harm are unavailable.
Impact: high · Exploitability: plausible
Developer action: Identify the affected package and installed version, confirm runtime reachability and advisory conditions, then update or pin a fixed version if applicable.
- Scanner
- osv-scanner 2.4.0
- Rule
- GHSA-23c5-xmqv-rm74
- File role
- production
- Source
- package-lock.json
Dependency advisory GHSA-3jxr-9vmj-r5cp applies
Material concern · low confidence
A dependency was matched to a high-severity security advisory, but the supplied evidence does not prove that the vulnerable behavior is used.
Technical evidence
Scanner reason: OSV-Scanner matched advisory GHSA-3jxr-9vmj-r5cp to a dependency declared by this repository.
Contextual assessment: The scanner identifies a high-severity advisory match without package details, installed version, reachability, attacker-controlled inputs, or concrete user impact.
Impact: high · Exploitability: plausible
Developer action: Identify the affected package and installed version, confirm runtime reachability and advisory conditions, then update or pin a fixed version if applicable.
- Scanner
- osv-scanner 2.4.0
- Rule
- GHSA-3jxr-9vmj-r5cp
- File role
- production
- Source
- package-lock.json
Dependency advisory GHSA-v56q-mh7h-f735 applies
Material concern · low confidence
A dependency was matched to a high-severity security advisory, but the evidence does not establish whether users are exposed through this extension.
Technical evidence
Scanner reason: OSV-Scanner matched advisory GHSA-v56q-mh7h-f735 to a dependency declared by this repository.
Contextual assessment: The supplied evidence contains only an advisory identifier and scanner result. It omits package identity, installed version, vulnerable functionality, runtime reachability, attacker control, and concrete harm.
Impact: high · Exploitability: plausible
Developer action: Identify the affected package and installed version, confirm runtime reachability and advisory conditions, then update or pin a fixed version if applicable.
- Scanner
- osv-scanner 2.4.0
- Rule
- GHSA-v56q-mh7h-f735
- File role
- production
- Source
- package-lock.json
Dependency advisory GHSA-7p8r-x3mc-p8w7 applies
Material concern · low confidence
A scanner found a known issue in a dependency, but the supplied evidence does not identify the package, installed version, or whether the extension uses the affected code.
Technical evidence
Scanner reason: OSV-Scanner matched advisory GHSA-7p8r-x3mc-p8w7 to a dependency declared by this repository.
Contextual assessment: The advisory match is only described as applying to a declared dependency. Package identity, resolved version, vulnerable range, runtime reachability, attacker-controlled input, and concrete impact are omitted, so immediate exploitability cannot be established.
Impact: medium · Exploitability: plausible
Developer action: Identify the affected package and locked version, then assess runtime reachability and update to a non-vulnerable version if applicable.
- Scanner
- osv-scanner 2.4.0
- Rule
- GHSA-7p8r-x3mc-p8w7
- File role
- production
- Source
- package-lock.json
Dependency advisory GHSA-28wg-ghj8-5hjv applies
Material concern · low confidence
A scanner found a known issue in a dependency, but the available report does not show whether this extension can trigger it.
Technical evidence
Scanner reason: OSV-Scanner matched advisory GHSA-28wg-ghj8-5hjv to a dependency declared by this repository.
Contextual assessment: Only an advisory identifier and generic dependency-match description are supplied. The affected package, resolved version, vulnerable code path, attacker control, and resulting harm are unavailable.
Impact: medium · Exploitability: plausible
Developer action: Identify the affected package and locked version, then assess runtime reachability and update to a non-vulnerable version if applicable.
- Scanner
- osv-scanner 2.4.0
- Rule
- GHSA-28wg-ghj8-5hjv
- File role
- production
- Source
- package-lock.json
Dependency advisory GHSA-7r86-cg39-jmmj applies
Material concern · low confidence
The scanner reports a dependency problem, but it does not provide enough detail to tell whether users are exposed.
Technical evidence
Scanner reason: OSV-Scanner matched advisory GHSA-7r86-cg39-jmmj to a dependency declared by this repository.
Contextual assessment: The evidence lacks package and version mapping, vulnerable-range confirmation, runtime reachability, attacker-controlled input analysis, and concrete impact.
Impact: medium · Exploitability: plausible
Developer action: Identify the affected package and locked version, then assess runtime reachability and update to a non-vulnerable version if applicable.
- Scanner
- osv-scanner 2.4.0
- Rule
- GHSA-7r86-cg39-jmmj
- File role
- production
- Source
- package-lock.json
Dependency advisory GHSA-8fgc-7cc6-rx7x applies
Material concern · low confidence
A low-severity dependency advisory was reported, but the affected component and practical exposure are not shown.
Technical evidence
Scanner reason: OSV-Scanner matched advisory GHSA-8fgc-7cc6-rx7x to a dependency declared by this repository.
Contextual assessment: The supplied metadata does not identify the dependency, installed version, reachability, input control, or concrete user harm. The finding therefore requires follow-up rather than dismissal.
Impact: low · Exploitability: plausible
Developer action: Identify the affected package and locked version, then assess runtime reachability and update to a non-vulnerable version if applicable.
- Scanner
- osv-scanner 2.4.0
- Rule
- GHSA-8fgc-7cc6-rx7x
- File role
- production
- Source
- package-lock.json
Dependency advisory GHSA-r28c-9q8g-f849 applies
Material concern · low confidence
A scanner found a high-severity issue somewhere in the dependency tree, but the supplied evidence cannot show whether the extension reaches it.
Technical evidence
Scanner reason: OSV-Scanner matched advisory GHSA-r28c-9q8g-f849 to a dependency declared by this repository.
Contextual assessment: No package name, resolved version, vulnerable range, runtime use, attacker-controlled path, or concrete consequence is supplied.
Impact: medium · Exploitability: plausible
Developer action: Identify the affected package and locked version, then assess runtime reachability and update to a non-vulnerable version if applicable.
- Scanner
- osv-scanner 2.4.0
- Rule
- GHSA-r28c-9q8g-f849
- File role
- production
- Source
- package-lock.json
Dependency advisory GHSA-xvcm-6775-5m9r applies
Material concern · low confidence
The report flags a dependency advisory, but not enough information is provided to determine actual user risk.
Technical evidence
Scanner reason: OSV-Scanner matched advisory GHSA-xvcm-6775-5m9r to a dependency declared by this repository.
Contextual assessment: The candidate lacks package/version identity and the data-flow details needed to determine whether vulnerable functionality is shipped and reachable.
Impact: medium · Exploitability: plausible
Developer action: Identify the affected package and locked version, then assess runtime reachability and update to a non-vulnerable version if applicable.
- Scanner
- osv-scanner 2.4.0
- Rule
- GHSA-xvcm-6775-5m9r
- File role
- production
- Source
- package-lock.json
Dependency advisory GHSA-3v7f-55p6-f55p applies
Material concern · low confidence
A medium-severity dependency issue was detected, but the supplied evidence does not establish whether it affects this extension in practice.
Technical evidence
Scanner reason: OSV-Scanner matched advisory GHSA-3v7f-55p6-f55p to a dependency declared by this repository.
Contextual assessment: The evidence provides only a generic advisory match; package identity, locked version, reachability, attacker input, and impact are omitted.
Impact: low · Exploitability: plausible
Developer action: Identify the affected package and locked version, then assess runtime reachability and update to a non-vulnerable version if applicable.
- Scanner
- osv-scanner 2.4.0
- Rule
- GHSA-3v7f-55p6-f55p
- File role
- production
- Source
- package-lock.json
Dependency advisory GHSA-4c8g-83qw-93j6 applies
Material concern · low confidence
A high-severity dependency advisory was reported, but the report does not show whether users can trigger the affected behavior.
Technical evidence
Scanner reason: OSV-Scanner matched advisory GHSA-4c8g-83qw-93j6 to a dependency declared by this repository.
Contextual assessment: Package details were removed, preventing comparison of the shipped version with the vulnerable range and analysis of runtime reachability or attacker-controlled data.
Impact: medium · Exploitability: plausible
Developer action: Identify the affected package and locked version, then assess runtime reachability and update to a non-vulnerable version if applicable.
- Scanner
- osv-scanner 2.4.0
- Rule
- GHSA-4c8g-83qw-93j6
- File role
- production
- Source
- package-lock.json
Dependency advisory GHSA-5p4m-2wfm-xmqj applies
Material concern · low confidence
A dependency in the production lockfile matches a published security advisory, but the supplied evidence does not identify the package, installed version, or whether the affected feature is used.
Technical evidence
Scanner reason: OSV-Scanner matched advisory GHSA-5p4m-2wfm-xmqj to a dependency declared by this repository.
Contextual assessment: The scanner reports a high-severity advisory for a declared dependency in the production lockfile. Package identity, resolved version, vulnerability condition, and runtime reachability were removed, so the concrete effect cannot be established from this evidence alone.
Impact: medium · Exploitability: plausible
Developer action: Identify the installed package and version, confirm runtime reachability and advisory conditions, then upgrade or constrain it if applicable.
- Scanner
- osv-scanner 2.4.0
- Rule
- GHSA-5p4m-2wfm-xmqj
- File role
- production
- Source
- package-lock.json
Dependency advisory GHSA-f886-m6hf-6m8v applies
Material concern · low confidence
A dependency in the production lockfile matches a published security advisory, but the supplied evidence does not identify the package, installed version, or whether the affected feature is used.
Technical evidence
Scanner reason: OSV-Scanner matched advisory GHSA-f886-m6hf-6m8v to a dependency declared by this repository.
Contextual assessment: The scanner reports a medium-severity advisory for a declared dependency in the production lockfile. Package identity, resolved version, vulnerability condition, and runtime reachability were removed, so the concrete effect cannot be established from this evidence alone.
Impact: medium · Exploitability: plausible
Developer action: Identify the installed package and version, confirm runtime reachability and advisory conditions, then upgrade or constrain it if applicable.
- Scanner
- osv-scanner 2.4.0
- Rule
- GHSA-f886-m6hf-6m8v
- File role
- production
- Source
- package-lock.json
Dependency advisory GHSA-52cp-r559-cp3m applies
Material concern · low confidence
A dependency in the production lockfile matches a published security advisory, but the supplied evidence does not identify the package, installed version, or whether the affected feature is used.
Technical evidence
Scanner reason: OSV-Scanner matched advisory GHSA-52cp-r559-cp3m to a dependency declared by this repository.
Contextual assessment: The scanner reports a high-severity advisory for a declared dependency in the production lockfile. Package identity, resolved version, vulnerability condition, and runtime reachability were removed, so the concrete effect cannot be established from this evidence alone.
Impact: medium · Exploitability: plausible
Developer action: Identify the installed package and version, confirm runtime reachability and advisory conditions, then upgrade or constrain it if applicable.
- Scanner
- osv-scanner 2.4.0
- Rule
- GHSA-52cp-r559-cp3m
- File role
- production
- Source
- package-lock.json
Dependency advisory GHSA-fxqj-rqcc-2cmp applies
Material concern · low confidence
A dependency in the production lockfile matches a published security advisory, but the supplied evidence does not identify the package, installed version, or whether the affected feature is used.
Technical evidence
Scanner reason: OSV-Scanner matched advisory GHSA-fxqj-rqcc-2cmp to a dependency declared by this repository.
Contextual assessment: The scanner reports a medium-severity advisory for a declared dependency in the production lockfile. Package identity, resolved version, vulnerability condition, and runtime reachability were removed, so the concrete effect cannot be established from this evidence alone.
Impact: medium · Exploitability: plausible
Developer action: Identify the installed package and version, confirm runtime reachability and advisory conditions, then upgrade or constrain it if applicable.
- Scanner
- osv-scanner 2.4.0
- Rule
- GHSA-fxqj-rqcc-2cmp
- File role
- production
- Source
- package-lock.json
Dependency advisory GHSA-3ppc-4f35-3m26 applies
Material concern · low confidence
A dependency in the production lockfile matches a published security advisory, but the supplied evidence does not identify the package, installed version, or whether the affected feature is used.
Technical evidence
Scanner reason: OSV-Scanner matched advisory GHSA-3ppc-4f35-3m26 to a dependency declared by this repository.
Contextual assessment: The scanner reports a high-severity advisory for a declared dependency in the production lockfile. Package identity, resolved version, vulnerability condition, and runtime reachability were removed, so the concrete effect cannot be established from this evidence alone.
Impact: medium · Exploitability: plausible
Developer action: Identify the installed package and version, confirm runtime reachability and advisory conditions, then upgrade or constrain it if applicable.
- Scanner
- osv-scanner 2.4.0
- Rule
- GHSA-3ppc-4f35-3m26
- File role
- production
- Source
- package-lock.json
Dependency advisory GHSA-mh99-v99m-4gvg applies
Material concern · low confidence
A dependency in the production lockfile matches a published security advisory, but the supplied evidence does not identify the package, installed version, or whether the affected feature is used.
Technical evidence
Scanner reason: OSV-Scanner matched advisory GHSA-mh99-v99m-4gvg to a dependency declared by this repository.
Contextual assessment: The scanner reports a high-severity advisory for a declared dependency in the production lockfile. Package identity, resolved version, vulnerability condition, and runtime reachability were removed, so the concrete effect cannot be established from this evidence alone.
Impact: medium · Exploitability: plausible
Developer action: Identify the installed package and version, confirm runtime reachability and advisory conditions, then upgrade or constrain it if applicable.
- Scanner
- osv-scanner 2.4.0
- Rule
- GHSA-mh99-v99m-4gvg
- File role
- production
- Source
- package-lock.json
Dependency advisory GHSA-c2c7-rcm5-vvqj applies
Material concern · low confidence
A dependency in the production lockfile matches a published security advisory, but the supplied evidence does not identify the package, installed version, or whether the affected feature is used.
Technical evidence
Scanner reason: OSV-Scanner matched advisory GHSA-c2c7-rcm5-vvqj to a dependency declared by this repository.
Contextual assessment: The scanner reports a high-severity advisory for a declared dependency in the production lockfile. Package identity, resolved version, vulnerability condition, and runtime reachability were removed, so the concrete effect cannot be established from this evidence alone.
Impact: medium · Exploitability: plausible
Developer action: Identify the installed package and version, confirm runtime reachability and advisory conditions, then upgrade or constrain it if applicable.
- Scanner
- osv-scanner 2.4.0
- Rule
- GHSA-c2c7-rcm5-vvqj
- File role
- production
- Source
- package-lock.json
Dependency advisory GHSA-48c2-rrv3-qjmp applies
Material concern · low confidence
A dependency in the production lockfile matches a published security advisory, but the supplied evidence does not identify the package, installed version, or whether the affected feature is used.
Technical evidence
Scanner reason: OSV-Scanner matched advisory GHSA-48c2-rrv3-qjmp to a dependency declared by this repository.
Contextual assessment: The scanner reports a medium-severity advisory for a declared dependency in the production lockfile. Package identity, resolved version, vulnerability condition, and runtime reachability were removed, so the concrete effect cannot be established from this evidence alone.
Impact: medium · Exploitability: plausible
Developer action: Identify the installed package and version, confirm runtime reachability and advisory conditions, then upgrade or constrain it if applicable.
- Scanner
- osv-scanner 2.4.0
- Rule
- GHSA-48c2-rrv3-qjmp
- File role
- production
- Source
- package-lock.json
Dependency advisory GHSA-2v37-7h3g-55p8 applies
Material concern · low confidence
A dependency in the lockfile matches a high-severity security advisory, but the supplied evidence does not identify the dependency or show whether the risky code runs in the installed extension.
Technical evidence
Scanner reason: OSV-Scanner matched advisory GHSA-2v37-7h3g-55p8 to a dependency declared by this repository.
Contextual assessment: The scanner reports a high-confidence match for GHSA-2v37-7h3g-55p8 in the production lockfile, but package identity, installed version, advisory condition, runtime reachability, and attacker-controlled input are absent. The finding warrants remediation analysis rather than an immediate-danger conclusion.
Impact: high · Exploitability: plausible
Developer action: Identify the matched package and shipped version, then assess whether the vulnerable code is included in the production bundle and reachable through extension inputs; upgrade or constrain it if reachable.
- Scanner
- osv-scanner 2.4.0
- Rule
- GHSA-2v37-7h3g-55p8
- File role
- production
- Source
- package-lock.json
Dependency advisory GHSA-38r7-794h-5758 applies
Material concern · low confidence
A dependency matches a low-severity security advisory, but there is not enough information to tell whether the affected feature is used by the extension.
Technical evidence
Scanner reason: OSV-Scanner matched advisory GHSA-38r7-794h-5758 to a dependency declared by this repository.
Contextual assessment: The scanner reports a high-confidence match for GHSA-38r7-794h-5758, yet the supplied context omits the package, version, affected component, reachability, and attacker control. Impact and exploitability therefore remain uncertain and require dependency-level triage.
Impact: medium · Exploitability: plausible
Developer action: Identify the matched package and shipped version, confirm runtime reachability and input control, and upgrade or constrain it where applicable.
- Scanner
- osv-scanner 2.4.0
- Rule
- GHSA-38r7-794h-5758
- File role
- production
- Source
- package-lock.json
Dependency advisory GHSA-rgw5-rvv9-x895 applies
Material concern · low confidence
A dependency in the lockfile matches a high-severity advisory, but the available information cannot show whether users can trigger the affected behavior.
Technical evidence
Scanner reason: OSV-Scanner matched advisory GHSA-rgw5-rvv9-x895 to a dependency declared by this repository.
Contextual assessment: The scanner reports a high-confidence match for GHSA-rgw5-rvv9-x895 in the production lockfile, while package identity, exact installed version, vulnerable functionality, runtime reachability, and attacker-controlled data flow are unavailable. This supports remediation and further validation, not a definitive immediate-danger rating.
Impact: high · Exploitability: plausible
Developer action: Identify the matched package and shipped version, determine whether the vulnerable path is bundled and reachable, and upgrade or constrain it if applicable.
- Scanner
- osv-scanner 2.4.0
- Rule
- GHSA-rgw5-rvv9-x895
- File role
- production
- Source
- package-lock.json
Expected scanner matches (7)
JavaScript analysis reported javascript.xray.serialize-environment
Expected behavior · high confidence
This is a normal production-build setting that controls whether the generated extension code is minimized. It does not show collection or transmission of credentials.
Technical evidence
Scanner reason: JavaScript analysis matched static JavaScript security signal javascript.xray.serialize-environment in this repository.
Contextual assessment: The cited line sets webpack minimization based on the build environment. The supplied source shows no runtime serialization, network destination, or credential handling associated with this signal.
Impact: none · Exploitability: unlikely
Developer action: none
- Scanner
- javascript-analysis webcrack-2.16.0_js-x-ray-16.0.0_signatures-1_literals-1
- Rule
- javascript.xray.serialize-environment
- File role
- tooling
- Source
- webpack.config.cjs:62
JavaScript analysis reported javascript.xray.prototype-pollution
Expected behavior · low confidence
The scanner found a generic pattern associated with prototype pollution in bundled JavaScript. The supplied excerpt does not show attacker-controlled data changing object prototypes or causing harmful behavior.
Technical evidence
Scanner reason: JavaScript analysis matched static JavaScript security signal javascript.xray.prototype-pollution in this repository.
Contextual assessment: The candidate is based on a fixed scanner signal in a minified bundle. Supplied context shows ordinary bundler helpers and application settings initialization, but no demonstrated attacker-controlled property assignment, prototype mutation, security-sensitive sink, or exploitable data flow. The signal is therefore insufficient to establish a vulnerability or malicious behavior.
Impact: none · Exploitability: unlikely
Developer action: none
- Scanner
- javascript-analysis webcrack-2.16.0_js-x-ray-16.0.0_signatures-1_literals-1
- Rule
- javascript.xray.prototype-pollution
- File role
- generated
- Source
- dist/index.js:8
JavaScript analysis reported javascript.xray.serialize-environment
Expected behavior · high confidence
This setting enables source maps during development, which helps debugging. It is not evidence that secrets are being sent anywhere.
Technical evidence
Scanner reason: JavaScript analysis matched static JavaScript security signal javascript.xray.serialize-environment in this repository.
Contextual assessment: The cited line selects a development source-map setting from the build environment. It is tooling-only and contains no runtime data flow or external destination.
Impact: none · Exploitability: unlikely
Developer action: none
- Scanner
- javascript-analysis webcrack-2.16.0_js-x-ray-16.0.0_signatures-1_literals-1
- Rule
- javascript.xray.serialize-environment
- File role
- tooling
- Source
- webpack.config.cjs:34
JavaScript analysis reported javascript.xray.obfuscated-code
Expected behavior · low confidence
The available excerpt shows ordinary bundled JavaScript and imports for SillyTavern features. The scanner reported a possible obfuscation signal, but the supplied evidence does not show hidden behavior, secret collection, or suspicious destinations.
Technical evidence
Scanner reason: JavaScript analysis matched static JavaScript security signal javascript.xray.obfuscated-code in this repository.
Contextual assessment: The candidate is a low-confidence static obfuscation signal in generated JavaScript. The supplied source context contains standard bundler-generated helpers and descriptive imports consistent with an extension that gathers story context and uses SillyTavern APIs. No concealed execution, credential access, exfiltration destination, or malicious persistence is evidenced.
Impact: none · Exploitability: unlikely
Developer action: none
- Scanner
- javascript-analysis webcrack-2.16.0_js-x-ray-16.0.0_signatures-1_literals-1
- Rule
- javascript.xray.obfuscated-code
- File role
- generated
- Source
- dist/index.js:1
JavaScript analysis reported javascript.xray.prototype-pollution
Expected behavior · high confidence
The flagged line is normal compiler-generated support code for JavaScript generator functions, not an operation that takes user data and changes unrelated objects.
Technical evidence
Scanner reason: JavaScript analysis matched static JavaScript security signal javascript.xray.prototype-pollution in this repository.
Contextual assessment: The supplied context shows a transpiled generator-runtime fallback assigning a generator prototype to a function through the legacy prototype property. The assigned value is a fixed internal runtime prototype, with no attacker-controlled property path, merge operation, or observable data flow to a security-sensitive destination. This is not evidence of exploitable prototype pollution in the extension logic or of malicious behavior.
Impact: none · Exploitability: unlikely
Developer action: none
- Scanner
- javascript-analysis webcrack-2.16.0_js-x-ray-16.0.0_signatures-1_literals-1
- Rule
- javascript.xray.prototype-pollution
- File role
- generated
- Source
- dist/index.js:3870
JavaScript analysis reported javascript.xray.serialize-environment
Expected behavior · high confidence
This controls whether TypeScript is type-checked during development builds. It does not access or leak user information.
Technical evidence
Scanner reason: JavaScript analysis matched static JavaScript security signal javascript.xray.serialize-environment in this repository.
Contextual assessment: The cited option configures ts-loader's development behavior. It changes compilation checks only and has no credential source, serialization destination, or runtime execution path.
Impact: none · Exploitability: unlikely
Developer action: none
- Scanner
- javascript-analysis webcrack-2.16.0_js-x-ray-16.0.0_signatures-1_literals-1
- Rule
- javascript.xray.serialize-environment
- File role
- tooling
- Source
- webpack.config.cjs:54
JavaScript analysis reported javascript.xray.serialize-environment
Expected behavior · high confidence
This selects the build mode based on the environment, a routine configuration choice. It does not indicate credential theft.
Technical evidence
Scanner reason: JavaScript analysis matched static JavaScript security signal javascript.xray.serialize-environment in this repository.
Contextual assessment: The cited expression chooses production or development webpack mode from an environment variable. In this tooling file it affects bundling behavior and does not establish runtime exfiltration.
Impact: none · Exploitability: unlikely
Developer action: none
- Scanner
- javascript-analysis webcrack-2.16.0_js-x-ray-16.0.0_signatures-1_literals-1
- Rule
- javascript.xray.serialize-environment
- File role
- tooling
- Source
- webpack.config.cjs:5