TavernKeeper Scan Report

bmen25124/SillyTavern-Roadway

Commit 8bd72bd Reviewed

35 material concerns identified.

This advisory report describes what the named tools and contextual reviewer found at one exact commit. Unknown or unobserved behavior may still exist.

0 immediate danger 35 material 7 low

What this review found

Dependency advisory GHSA-v6h2-p8h4-qcjw applies

Material concern · low confidence

A scanner found a known issue in one dependency, but the supplied evidence does not say which package or whether the extension uses the affected code.

Technical evidence

Scanner reason: OSV-Scanner matched advisory GHSA-v6h2-p8h4-qcjw to a dependency declared by this repository.

Contextual assessment: The advisory match is present in the production lockfile, but package identity, installed version, vulnerable component, reachability, attacker-controlled input, and concrete impact are omitted. The finding therefore cannot be reduced to a low-risk conclusion from the supplied context.

Impact: medium · Exploitability: plausible

Developer action: Identify the affected package and installed version, confirm runtime reachability, then update to a fixed version if applicable.

Scanner
osv-scanner 2.4.0
Rule
GHSA-v6h2-p8h4-qcjw
File role
production
Source
package-lock.json

Dependency advisory GHSA-4x5r-pxfx-6jf8 applies

Material concern · low confidence

A scanner found a known issue in one dependency, but the available report does not show whether it affects the extension during normal use.

Technical evidence

Scanner reason: OSV-Scanner matched advisory GHSA-4x5r-pxfx-6jf8 to a dependency declared by this repository.

Contextual assessment: The advisory match is reported for the shipped lockfile, while package/version and runtime data were removed. Exploitability and impact cannot be determined without mapping the advisory to the resolved dependency and execution path.

Impact: medium · Exploitability: plausible

Developer action: Identify the affected package and installed version, confirm runtime reachability, then update to a fixed version if applicable.

Scanner
osv-scanner 2.4.0
Rule
GHSA-4x5r-pxfx-6jf8
File role
production
Source
package-lock.json

Dependency advisory GHSA-fv7c-fp4j-7gwp applies

Material concern · low confidence

A high-severity advisory was detected, but the evidence does not reveal what library is affected or whether users can reach the vulnerable behavior.

Technical evidence

Scanner reason: OSV-Scanner matched advisory GHSA-fv7c-fp4j-7gwp to a dependency declared by this repository.

Contextual assessment: The scanner reports a high-severity advisory in the production lockfile, but omits package identity, resolved version, vulnerable function, reachability, and input control. High scanner severity alone does not establish immediate danger.

Impact: high · Exploitability: plausible

Developer action: Identify the affected package and installed version, assess runtime reachability and attacker-controlled inputs, and update to a fixed version if applicable.

Scanner
osv-scanner 2.4.0
Rule
GHSA-fv7c-fp4j-7gwp
File role
production
Source
package-lock.json

Dependency advisory GHSA-mh29-5h37-fv8m applies

Material concern · low confidence

A scanner reported a medium-severity dependency problem, but more information is needed to know whether it can affect extension users.

Technical evidence

Scanner reason: OSV-Scanner matched advisory GHSA-mh29-5h37-fv8m to a dependency declared by this repository.

Contextual assessment: The lockfile contains an advisory match, but the affected dependency, version, reachability, and concrete harm are not supplied. This supports remediation and investigation, not a definitive exploitability conclusion.

Impact: medium · Exploitability: plausible

Developer action: Identify the affected package and installed version, determine whether the vulnerable path is reachable, and update to a fixed version if applicable.

Scanner
osv-scanner 2.4.0
Rule
GHSA-mh29-5h37-fv8m
File role
production
Source
package-lock.json

Dependency advisory GHSA-qj8w-gfj5-8c6v applies

Material concern · low confidence

A scanner reported a dependency issue, but the supplied evidence does not show whether normal Roadway use triggers it.

Technical evidence

Scanner reason: OSV-Scanner matched advisory GHSA-qj8w-gfj5-8c6v to a dependency declared by this repository.

Contextual assessment: The advisory is associated with the shipped lockfile, while the dependency name, version, vulnerable code path, and attacker-control conditions are absent. Contextual assessment remains material pending those details.

Impact: medium · Exploitability: plausible

Developer action: Identify the affected package and installed version, determine whether the vulnerable path is reachable, and update to a fixed version if applicable.

Scanner
osv-scanner 2.4.0
Rule
GHSA-qj8w-gfj5-8c6v
File role
production
Source
package-lock.json

Dependency advisory GHSA-5c6j-r48x-rmvq applies

Material concern · low confidence

A high-severity dependency advisory was found, but the report does not provide enough detail to tell whether users face that risk in this extension.

Technical evidence

Scanner reason: OSV-Scanner matched advisory GHSA-5c6j-r48x-rmvq to a dependency declared by this repository.

Contextual assessment: The scanner identifies a high-severity advisory but withholds package and version details and supplies no runtime reachability or exploit preconditions. Immediate high risk is not established, but remediation should be investigated.

Impact: high · Exploitability: plausible

Developer action: Identify the affected package and installed version, assess reachability and input control, and update to a fixed version if applicable.

Scanner
osv-scanner 2.4.0
Rule
GHSA-5c6j-r48x-rmvq
File role
production
Source
package-lock.json

Dependency advisory GHSA-v2hh-gcrm-f6hx applies

Material concern · low confidence

A high-severity library issue was detected, but the evidence does not show which library is involved or whether Roadway can invoke the vulnerable behavior.

Technical evidence

Scanner reason: OSV-Scanner matched advisory GHSA-v2hh-gcrm-f6hx to a dependency declared by this repository.

Contextual assessment: The lockfile advisory match lacks the package, resolved version, vulnerable operation, reachability, and attacker-control analysis required to establish immediate danger. Treat as a remediation candidate pending dependency mapping.

Impact: high · Exploitability: plausible

Developer action: Identify the affected package and installed version, assess reachability and input control, and update to a fixed version if applicable.

Scanner
osv-scanner 2.4.0
Rule
GHSA-v2hh-gcrm-f6hx
File role
production
Source
package-lock.json

Dependency advisory GHSA-968p-4wvh-cqc8 applies

Material concern · low confidence

A scanner found a medium-severity issue in a dependency, but the supplied report does not show whether it affects users of the extension.

Technical evidence

Scanner reason: OSV-Scanner matched advisory GHSA-968p-4wvh-cqc8 to a dependency declared by this repository.

Contextual assessment: The advisory is reported against the shipped lockfile, but package identity, resolved version, runtime use, and exploit conditions are unavailable. A low-risk conclusion would be unsupported.

Impact: medium · Exploitability: plausible

Developer action: Identify the affected package and installed version, confirm runtime reachability, and update to a fixed version if applicable.

Scanner
osv-scanner 2.4.0
Rule
GHSA-968p-4wvh-cqc8
File role
production
Source
package-lock.json

Dependency advisory GHSA-2g4f-4pwh-qvx6 applies

Material concern · low confidence

A dependency was matched to a published security advisory, but the supplied evidence does not identify the package, version, or whether the vulnerable feature is used.

Technical evidence

Scanner reason: OSV-Scanner matched advisory GHSA-2g4f-4pwh-qvx6 to a dependency declared by this repository.

Contextual assessment: The scanner reports an advisory match in the production lockfile, but package details, installed version, vulnerable code path, attacker-controlled input, and runtime reachability are absent. The finding cannot be reduced to a confirmed runtime issue from this evidence alone.

Impact: medium · Exploitability: plausible

Developer action: Identify the affected package and installed version, confirm runtime reachability and advisory conditions, then update or pin a fixed version if applicable.

Scanner
osv-scanner 2.4.0
Rule
GHSA-2g4f-4pwh-qvx6
File role
production
Source
package-lock.json

Dependency advisory GHSA-v39h-62p7-jpjc applies

Material concern · low confidence

A dependency was matched to a high-severity security advisory, but the supplied evidence does not show which package is involved or whether users can trigger the vulnerable behavior.

Technical evidence

Scanner reason: OSV-Scanner matched advisory GHSA-v39h-62p7-jpjc to a dependency declared by this repository.

Contextual assessment: The scanner reports a high-severity advisory match in the production lockfile, but omits package identity, installed version, reachability, input control, and concrete impact. Severity alone does not establish an immediately exploitable runtime vulnerability.

Impact: high · Exploitability: plausible

Developer action: Identify the affected package and installed version, confirm runtime reachability and advisory conditions, then update or pin a fixed version if applicable.

Scanner
osv-scanner 2.4.0
Rule
GHSA-v39h-62p7-jpjc
File role
production
Source
package-lock.json

Dependency advisory GHSA-h67p-54hq-rp68 applies

Material concern · low confidence

A dependency was matched to a published security advisory, but there is not enough information to tell whether the vulnerable part is used by the extension.

Technical evidence

Scanner reason: OSV-Scanner matched advisory GHSA-h67p-54hq-rp68 to a dependency declared by this repository.

Contextual assessment: The scanner reports an advisory match, while the supplied context lacks package/version mapping, vulnerable range, runtime reachability, attacker-controlled input, and resulting harm.

Impact: medium · Exploitability: plausible

Developer action: Identify the affected package and installed version, confirm runtime reachability and advisory conditions, then update or pin a fixed version if applicable.

Scanner
osv-scanner 2.4.0
Rule
GHSA-h67p-54hq-rp68
File role
production
Source
package-lock.json

Dependency advisory GHSA-q3j6-qgpj-74h6 applies

Material concern · low confidence

A dependency was matched to a high-severity security advisory, but the evidence does not establish that the extension reaches the affected code.

Technical evidence

Scanner reason: OSV-Scanner matched advisory GHSA-q3j6-qgpj-74h6 to a dependency declared by this repository.

Contextual assessment: The finding is limited to a high-severity advisory identifier associated with a lockfile dependency. Package identity, version, runtime use, attacker input, and exploit conditions were removed.

Impact: high · Exploitability: plausible

Developer action: Identify the affected package and installed version, confirm runtime reachability and advisory conditions, then update or pin a fixed version if applicable.

Scanner
osv-scanner 2.4.0
Rule
GHSA-q3j6-qgpj-74h6
File role
production
Source
package-lock.json

Dependency advisory GHSA-wf6x-7x77-mvgw applies

Material concern · low confidence

A dependency was matched to a high-severity security advisory, but the supplied evidence does not show whether this affects the shipped extension.

Technical evidence

Scanner reason: OSV-Scanner matched advisory GHSA-wf6x-7x77-mvgw to a dependency declared by this repository.

Contextual assessment: The scanner reports a high-severity advisory match, but does not provide the affected package, installed version, reachable feature, attacker-controlled input, or concrete impact.

Impact: high · Exploitability: plausible

Developer action: Identify the affected package and installed version, confirm runtime reachability and advisory conditions, then update or pin a fixed version if applicable.

Scanner
osv-scanner 2.4.0
Rule
GHSA-wf6x-7x77-mvgw
File role
production
Source
package-lock.json

Dependency advisory GHSA-23c5-xmqv-rm74 applies

Material concern · low confidence

A dependency was matched to a high-severity security advisory, but the evidence is insufficient to determine whether it can affect users of this extension.

Technical evidence

Scanner reason: OSV-Scanner matched advisory GHSA-23c5-xmqv-rm74 to a dependency declared by this repository.

Contextual assessment: Only the advisory match and scanner severity are supplied. The package/version, affected code path, runtime reachability, attacker control, and harm are unavailable.

Impact: high · Exploitability: plausible

Developer action: Identify the affected package and installed version, confirm runtime reachability and advisory conditions, then update or pin a fixed version if applicable.

Scanner
osv-scanner 2.4.0
Rule
GHSA-23c5-xmqv-rm74
File role
production
Source
package-lock.json

Dependency advisory GHSA-3jxr-9vmj-r5cp applies

Material concern · low confidence

A dependency was matched to a high-severity security advisory, but the supplied evidence does not prove that the vulnerable behavior is used.

Technical evidence

Scanner reason: OSV-Scanner matched advisory GHSA-3jxr-9vmj-r5cp to a dependency declared by this repository.

Contextual assessment: The scanner identifies a high-severity advisory match without package details, installed version, reachability, attacker-controlled inputs, or concrete user impact.

Impact: high · Exploitability: plausible

Developer action: Identify the affected package and installed version, confirm runtime reachability and advisory conditions, then update or pin a fixed version if applicable.

Scanner
osv-scanner 2.4.0
Rule
GHSA-3jxr-9vmj-r5cp
File role
production
Source
package-lock.json

Dependency advisory GHSA-v56q-mh7h-f735 applies

Material concern · low confidence

A dependency was matched to a high-severity security advisory, but the evidence does not establish whether users are exposed through this extension.

Technical evidence

Scanner reason: OSV-Scanner matched advisory GHSA-v56q-mh7h-f735 to a dependency declared by this repository.

Contextual assessment: The supplied evidence contains only an advisory identifier and scanner result. It omits package identity, installed version, vulnerable functionality, runtime reachability, attacker control, and concrete harm.

Impact: high · Exploitability: plausible

Developer action: Identify the affected package and installed version, confirm runtime reachability and advisory conditions, then update or pin a fixed version if applicable.

Scanner
osv-scanner 2.4.0
Rule
GHSA-v56q-mh7h-f735
File role
production
Source
package-lock.json

Dependency advisory GHSA-7p8r-x3mc-p8w7 applies

Material concern · low confidence

A scanner found a known issue in a dependency, but the supplied evidence does not identify the package, installed version, or whether the extension uses the affected code.

Technical evidence

Scanner reason: OSV-Scanner matched advisory GHSA-7p8r-x3mc-p8w7 to a dependency declared by this repository.

Contextual assessment: The advisory match is only described as applying to a declared dependency. Package identity, resolved version, vulnerable range, runtime reachability, attacker-controlled input, and concrete impact are omitted, so immediate exploitability cannot be established.

Impact: medium · Exploitability: plausible

Developer action: Identify the affected package and locked version, then assess runtime reachability and update to a non-vulnerable version if applicable.

Scanner
osv-scanner 2.4.0
Rule
GHSA-7p8r-x3mc-p8w7
File role
production
Source
package-lock.json

Dependency advisory GHSA-28wg-ghj8-5hjv applies

Material concern · low confidence

A scanner found a known issue in a dependency, but the available report does not show whether this extension can trigger it.

Technical evidence

Scanner reason: OSV-Scanner matched advisory GHSA-28wg-ghj8-5hjv to a dependency declared by this repository.

Contextual assessment: Only an advisory identifier and generic dependency-match description are supplied. The affected package, resolved version, vulnerable code path, attacker control, and resulting harm are unavailable.

Impact: medium · Exploitability: plausible

Developer action: Identify the affected package and locked version, then assess runtime reachability and update to a non-vulnerable version if applicable.

Scanner
osv-scanner 2.4.0
Rule
GHSA-28wg-ghj8-5hjv
File role
production
Source
package-lock.json

Dependency advisory GHSA-7r86-cg39-jmmj applies

Material concern · low confidence

The scanner reports a dependency problem, but it does not provide enough detail to tell whether users are exposed.

Technical evidence

Scanner reason: OSV-Scanner matched advisory GHSA-7r86-cg39-jmmj to a dependency declared by this repository.

Contextual assessment: The evidence lacks package and version mapping, vulnerable-range confirmation, runtime reachability, attacker-controlled input analysis, and concrete impact.

Impact: medium · Exploitability: plausible

Developer action: Identify the affected package and locked version, then assess runtime reachability and update to a non-vulnerable version if applicable.

Scanner
osv-scanner 2.4.0
Rule
GHSA-7r86-cg39-jmmj
File role
production
Source
package-lock.json

Dependency advisory GHSA-8fgc-7cc6-rx7x applies

Material concern · low confidence

A low-severity dependency advisory was reported, but the affected component and practical exposure are not shown.

Technical evidence

Scanner reason: OSV-Scanner matched advisory GHSA-8fgc-7cc6-rx7x to a dependency declared by this repository.

Contextual assessment: The supplied metadata does not identify the dependency, installed version, reachability, input control, or concrete user harm. The finding therefore requires follow-up rather than dismissal.

Impact: low · Exploitability: plausible

Developer action: Identify the affected package and locked version, then assess runtime reachability and update to a non-vulnerable version if applicable.

Scanner
osv-scanner 2.4.0
Rule
GHSA-8fgc-7cc6-rx7x
File role
production
Source
package-lock.json

Dependency advisory GHSA-r28c-9q8g-f849 applies

Material concern · low confidence

A scanner found a high-severity issue somewhere in the dependency tree, but the supplied evidence cannot show whether the extension reaches it.

Technical evidence

Scanner reason: OSV-Scanner matched advisory GHSA-r28c-9q8g-f849 to a dependency declared by this repository.

Contextual assessment: No package name, resolved version, vulnerable range, runtime use, attacker-controlled path, or concrete consequence is supplied.

Impact: medium · Exploitability: plausible

Developer action: Identify the affected package and locked version, then assess runtime reachability and update to a non-vulnerable version if applicable.

Scanner
osv-scanner 2.4.0
Rule
GHSA-r28c-9q8g-f849
File role
production
Source
package-lock.json

Dependency advisory GHSA-xvcm-6775-5m9r applies

Material concern · low confidence

The report flags a dependency advisory, but not enough information is provided to determine actual user risk.

Technical evidence

Scanner reason: OSV-Scanner matched advisory GHSA-xvcm-6775-5m9r to a dependency declared by this repository.

Contextual assessment: The candidate lacks package/version identity and the data-flow details needed to determine whether vulnerable functionality is shipped and reachable.

Impact: medium · Exploitability: plausible

Developer action: Identify the affected package and locked version, then assess runtime reachability and update to a non-vulnerable version if applicable.

Scanner
osv-scanner 2.4.0
Rule
GHSA-xvcm-6775-5m9r
File role
production
Source
package-lock.json

Dependency advisory GHSA-3v7f-55p6-f55p applies

Material concern · low confidence

A medium-severity dependency issue was detected, but the supplied evidence does not establish whether it affects this extension in practice.

Technical evidence

Scanner reason: OSV-Scanner matched advisory GHSA-3v7f-55p6-f55p to a dependency declared by this repository.

Contextual assessment: The evidence provides only a generic advisory match; package identity, locked version, reachability, attacker input, and impact are omitted.

Impact: low · Exploitability: plausible

Developer action: Identify the affected package and locked version, then assess runtime reachability and update to a non-vulnerable version if applicable.

Scanner
osv-scanner 2.4.0
Rule
GHSA-3v7f-55p6-f55p
File role
production
Source
package-lock.json

Dependency advisory GHSA-4c8g-83qw-93j6 applies

Material concern · low confidence

A high-severity dependency advisory was reported, but the report does not show whether users can trigger the affected behavior.

Technical evidence

Scanner reason: OSV-Scanner matched advisory GHSA-4c8g-83qw-93j6 to a dependency declared by this repository.

Contextual assessment: Package details were removed, preventing comparison of the shipped version with the vulnerable range and analysis of runtime reachability or attacker-controlled data.

Impact: medium · Exploitability: plausible

Developer action: Identify the affected package and locked version, then assess runtime reachability and update to a non-vulnerable version if applicable.

Scanner
osv-scanner 2.4.0
Rule
GHSA-4c8g-83qw-93j6
File role
production
Source
package-lock.json

Dependency advisory GHSA-5p4m-2wfm-xmqj applies

Material concern · low confidence

A dependency in the production lockfile matches a published security advisory, but the supplied evidence does not identify the package, installed version, or whether the affected feature is used.

Technical evidence

Scanner reason: OSV-Scanner matched advisory GHSA-5p4m-2wfm-xmqj to a dependency declared by this repository.

Contextual assessment: The scanner reports a high-severity advisory for a declared dependency in the production lockfile. Package identity, resolved version, vulnerability condition, and runtime reachability were removed, so the concrete effect cannot be established from this evidence alone.

Impact: medium · Exploitability: plausible

Developer action: Identify the installed package and version, confirm runtime reachability and advisory conditions, then upgrade or constrain it if applicable.

Scanner
osv-scanner 2.4.0
Rule
GHSA-5p4m-2wfm-xmqj
File role
production
Source
package-lock.json

Dependency advisory GHSA-f886-m6hf-6m8v applies

Material concern · low confidence

A dependency in the production lockfile matches a published security advisory, but the supplied evidence does not identify the package, installed version, or whether the affected feature is used.

Technical evidence

Scanner reason: OSV-Scanner matched advisory GHSA-f886-m6hf-6m8v to a dependency declared by this repository.

Contextual assessment: The scanner reports a medium-severity advisory for a declared dependency in the production lockfile. Package identity, resolved version, vulnerability condition, and runtime reachability were removed, so the concrete effect cannot be established from this evidence alone.

Impact: medium · Exploitability: plausible

Developer action: Identify the installed package and version, confirm runtime reachability and advisory conditions, then upgrade or constrain it if applicable.

Scanner
osv-scanner 2.4.0
Rule
GHSA-f886-m6hf-6m8v
File role
production
Source
package-lock.json

Dependency advisory GHSA-52cp-r559-cp3m applies

Material concern · low confidence

A dependency in the production lockfile matches a published security advisory, but the supplied evidence does not identify the package, installed version, or whether the affected feature is used.

Technical evidence

Scanner reason: OSV-Scanner matched advisory GHSA-52cp-r559-cp3m to a dependency declared by this repository.

Contextual assessment: The scanner reports a high-severity advisory for a declared dependency in the production lockfile. Package identity, resolved version, vulnerability condition, and runtime reachability were removed, so the concrete effect cannot be established from this evidence alone.

Impact: medium · Exploitability: plausible

Developer action: Identify the installed package and version, confirm runtime reachability and advisory conditions, then upgrade or constrain it if applicable.

Scanner
osv-scanner 2.4.0
Rule
GHSA-52cp-r559-cp3m
File role
production
Source
package-lock.json

Dependency advisory GHSA-fxqj-rqcc-2cmp applies

Material concern · low confidence

A dependency in the production lockfile matches a published security advisory, but the supplied evidence does not identify the package, installed version, or whether the affected feature is used.

Technical evidence

Scanner reason: OSV-Scanner matched advisory GHSA-fxqj-rqcc-2cmp to a dependency declared by this repository.

Contextual assessment: The scanner reports a medium-severity advisory for a declared dependency in the production lockfile. Package identity, resolved version, vulnerability condition, and runtime reachability were removed, so the concrete effect cannot be established from this evidence alone.

Impact: medium · Exploitability: plausible

Developer action: Identify the installed package and version, confirm runtime reachability and advisory conditions, then upgrade or constrain it if applicable.

Scanner
osv-scanner 2.4.0
Rule
GHSA-fxqj-rqcc-2cmp
File role
production
Source
package-lock.json

Dependency advisory GHSA-3ppc-4f35-3m26 applies

Material concern · low confidence

A dependency in the production lockfile matches a published security advisory, but the supplied evidence does not identify the package, installed version, or whether the affected feature is used.

Technical evidence

Scanner reason: OSV-Scanner matched advisory GHSA-3ppc-4f35-3m26 to a dependency declared by this repository.

Contextual assessment: The scanner reports a high-severity advisory for a declared dependency in the production lockfile. Package identity, resolved version, vulnerability condition, and runtime reachability were removed, so the concrete effect cannot be established from this evidence alone.

Impact: medium · Exploitability: plausible

Developer action: Identify the installed package and version, confirm runtime reachability and advisory conditions, then upgrade or constrain it if applicable.

Scanner
osv-scanner 2.4.0
Rule
GHSA-3ppc-4f35-3m26
File role
production
Source
package-lock.json

Dependency advisory GHSA-mh99-v99m-4gvg applies

Material concern · low confidence

A dependency in the production lockfile matches a published security advisory, but the supplied evidence does not identify the package, installed version, or whether the affected feature is used.

Technical evidence

Scanner reason: OSV-Scanner matched advisory GHSA-mh99-v99m-4gvg to a dependency declared by this repository.

Contextual assessment: The scanner reports a high-severity advisory for a declared dependency in the production lockfile. Package identity, resolved version, vulnerability condition, and runtime reachability were removed, so the concrete effect cannot be established from this evidence alone.

Impact: medium · Exploitability: plausible

Developer action: Identify the installed package and version, confirm runtime reachability and advisory conditions, then upgrade or constrain it if applicable.

Scanner
osv-scanner 2.4.0
Rule
GHSA-mh99-v99m-4gvg
File role
production
Source
package-lock.json

Dependency advisory GHSA-c2c7-rcm5-vvqj applies

Material concern · low confidence

A dependency in the production lockfile matches a published security advisory, but the supplied evidence does not identify the package, installed version, or whether the affected feature is used.

Technical evidence

Scanner reason: OSV-Scanner matched advisory GHSA-c2c7-rcm5-vvqj to a dependency declared by this repository.

Contextual assessment: The scanner reports a high-severity advisory for a declared dependency in the production lockfile. Package identity, resolved version, vulnerability condition, and runtime reachability were removed, so the concrete effect cannot be established from this evidence alone.

Impact: medium · Exploitability: plausible

Developer action: Identify the installed package and version, confirm runtime reachability and advisory conditions, then upgrade or constrain it if applicable.

Scanner
osv-scanner 2.4.0
Rule
GHSA-c2c7-rcm5-vvqj
File role
production
Source
package-lock.json

Dependency advisory GHSA-48c2-rrv3-qjmp applies

Material concern · low confidence

A dependency in the production lockfile matches a published security advisory, but the supplied evidence does not identify the package, installed version, or whether the affected feature is used.

Technical evidence

Scanner reason: OSV-Scanner matched advisory GHSA-48c2-rrv3-qjmp to a dependency declared by this repository.

Contextual assessment: The scanner reports a medium-severity advisory for a declared dependency in the production lockfile. Package identity, resolved version, vulnerability condition, and runtime reachability were removed, so the concrete effect cannot be established from this evidence alone.

Impact: medium · Exploitability: plausible

Developer action: Identify the installed package and version, confirm runtime reachability and advisory conditions, then upgrade or constrain it if applicable.

Scanner
osv-scanner 2.4.0
Rule
GHSA-48c2-rrv3-qjmp
File role
production
Source
package-lock.json

Dependency advisory GHSA-2v37-7h3g-55p8 applies

Material concern · low confidence

A dependency in the lockfile matches a high-severity security advisory, but the supplied evidence does not identify the dependency or show whether the risky code runs in the installed extension.

Technical evidence

Scanner reason: OSV-Scanner matched advisory GHSA-2v37-7h3g-55p8 to a dependency declared by this repository.

Contextual assessment: The scanner reports a high-confidence match for GHSA-2v37-7h3g-55p8 in the production lockfile, but package identity, installed version, advisory condition, runtime reachability, and attacker-controlled input are absent. The finding warrants remediation analysis rather than an immediate-danger conclusion.

Impact: high · Exploitability: plausible

Developer action: Identify the matched package and shipped version, then assess whether the vulnerable code is included in the production bundle and reachable through extension inputs; upgrade or constrain it if reachable.

Scanner
osv-scanner 2.4.0
Rule
GHSA-2v37-7h3g-55p8
File role
production
Source
package-lock.json

Dependency advisory GHSA-38r7-794h-5758 applies

Material concern · low confidence

A dependency matches a low-severity security advisory, but there is not enough information to tell whether the affected feature is used by the extension.

Technical evidence

Scanner reason: OSV-Scanner matched advisory GHSA-38r7-794h-5758 to a dependency declared by this repository.

Contextual assessment: The scanner reports a high-confidence match for GHSA-38r7-794h-5758, yet the supplied context omits the package, version, affected component, reachability, and attacker control. Impact and exploitability therefore remain uncertain and require dependency-level triage.

Impact: medium · Exploitability: plausible

Developer action: Identify the matched package and shipped version, confirm runtime reachability and input control, and upgrade or constrain it where applicable.

Scanner
osv-scanner 2.4.0
Rule
GHSA-38r7-794h-5758
File role
production
Source
package-lock.json

Dependency advisory GHSA-rgw5-rvv9-x895 applies

Material concern · low confidence

A dependency in the lockfile matches a high-severity advisory, but the available information cannot show whether users can trigger the affected behavior.

Technical evidence

Scanner reason: OSV-Scanner matched advisory GHSA-rgw5-rvv9-x895 to a dependency declared by this repository.

Contextual assessment: The scanner reports a high-confidence match for GHSA-rgw5-rvv9-x895 in the production lockfile, while package identity, exact installed version, vulnerable functionality, runtime reachability, and attacker-controlled data flow are unavailable. This supports remediation and further validation, not a definitive immediate-danger rating.

Impact: high · Exploitability: plausible

Developer action: Identify the matched package and shipped version, determine whether the vulnerable path is bundled and reachable, and upgrade or constrain it if applicable.

Scanner
osv-scanner 2.4.0
Rule
GHSA-rgw5-rvv9-x895
File role
production
Source
package-lock.json
Expected scanner matches (7)

JavaScript analysis reported javascript.xray.serialize-environment

Expected behavior · high confidence

This is a normal production-build setting that controls whether the generated extension code is minimized. It does not show collection or transmission of credentials.

Technical evidence

Scanner reason: JavaScript analysis matched static JavaScript security signal javascript.xray.serialize-environment in this repository.

Contextual assessment: The cited line sets webpack minimization based on the build environment. The supplied source shows no runtime serialization, network destination, or credential handling associated with this signal.

Impact: none · Exploitability: unlikely

Developer action: none

Scanner
javascript-analysis webcrack-2.16.0_js-x-ray-16.0.0_signatures-1_literals-1
Rule
javascript.xray.serialize-environment
File role
tooling
Source
webpack.config.cjs:62

JavaScript analysis reported javascript.xray.prototype-pollution

Expected behavior · low confidence

The scanner found a generic pattern associated with prototype pollution in bundled JavaScript. The supplied excerpt does not show attacker-controlled data changing object prototypes or causing harmful behavior.

Technical evidence

Scanner reason: JavaScript analysis matched static JavaScript security signal javascript.xray.prototype-pollution in this repository.

Contextual assessment: The candidate is based on a fixed scanner signal in a minified bundle. Supplied context shows ordinary bundler helpers and application settings initialization, but no demonstrated attacker-controlled property assignment, prototype mutation, security-sensitive sink, or exploitable data flow. The signal is therefore insufficient to establish a vulnerability or malicious behavior.

Impact: none · Exploitability: unlikely

Developer action: none

Scanner
javascript-analysis webcrack-2.16.0_js-x-ray-16.0.0_signatures-1_literals-1
Rule
javascript.xray.prototype-pollution
File role
generated
Source
dist/index.js:8

JavaScript analysis reported javascript.xray.serialize-environment

Expected behavior · high confidence

This setting enables source maps during development, which helps debugging. It is not evidence that secrets are being sent anywhere.

Technical evidence

Scanner reason: JavaScript analysis matched static JavaScript security signal javascript.xray.serialize-environment in this repository.

Contextual assessment: The cited line selects a development source-map setting from the build environment. It is tooling-only and contains no runtime data flow or external destination.

Impact: none · Exploitability: unlikely

Developer action: none

Scanner
javascript-analysis webcrack-2.16.0_js-x-ray-16.0.0_signatures-1_literals-1
Rule
javascript.xray.serialize-environment
File role
tooling
Source
webpack.config.cjs:34

JavaScript analysis reported javascript.xray.obfuscated-code

Expected behavior · low confidence

The available excerpt shows ordinary bundled JavaScript and imports for SillyTavern features. The scanner reported a possible obfuscation signal, but the supplied evidence does not show hidden behavior, secret collection, or suspicious destinations.

Technical evidence

Scanner reason: JavaScript analysis matched static JavaScript security signal javascript.xray.obfuscated-code in this repository.

Contextual assessment: The candidate is a low-confidence static obfuscation signal in generated JavaScript. The supplied source context contains standard bundler-generated helpers and descriptive imports consistent with an extension that gathers story context and uses SillyTavern APIs. No concealed execution, credential access, exfiltration destination, or malicious persistence is evidenced.

Impact: none · Exploitability: unlikely

Developer action: none

Scanner
javascript-analysis webcrack-2.16.0_js-x-ray-16.0.0_signatures-1_literals-1
Rule
javascript.xray.obfuscated-code
File role
generated
Source
dist/index.js:1

JavaScript analysis reported javascript.xray.prototype-pollution

Expected behavior · high confidence

The flagged line is normal compiler-generated support code for JavaScript generator functions, not an operation that takes user data and changes unrelated objects.

Technical evidence

Scanner reason: JavaScript analysis matched static JavaScript security signal javascript.xray.prototype-pollution in this repository.

Contextual assessment: The supplied context shows a transpiled generator-runtime fallback assigning a generator prototype to a function through the legacy prototype property. The assigned value is a fixed internal runtime prototype, with no attacker-controlled property path, merge operation, or observable data flow to a security-sensitive destination. This is not evidence of exploitable prototype pollution in the extension logic or of malicious behavior.

Impact: none · Exploitability: unlikely

Developer action: none

Scanner
javascript-analysis webcrack-2.16.0_js-x-ray-16.0.0_signatures-1_literals-1
Rule
javascript.xray.prototype-pollution
File role
generated
Source
dist/index.js:3870

JavaScript analysis reported javascript.xray.serialize-environment

Expected behavior · high confidence

This controls whether TypeScript is type-checked during development builds. It does not access or leak user information.

Technical evidence

Scanner reason: JavaScript analysis matched static JavaScript security signal javascript.xray.serialize-environment in this repository.

Contextual assessment: The cited option configures ts-loader's development behavior. It changes compilation checks only and has no credential source, serialization destination, or runtime execution path.

Impact: none · Exploitability: unlikely

Developer action: none

Scanner
javascript-analysis webcrack-2.16.0_js-x-ray-16.0.0_signatures-1_literals-1
Rule
javascript.xray.serialize-environment
File role
tooling
Source
webpack.config.cjs:54

JavaScript analysis reported javascript.xray.serialize-environment

Expected behavior · high confidence

This selects the build mode based on the environment, a routine configuration choice. It does not indicate credential theft.

Technical evidence

Scanner reason: JavaScript analysis matched static JavaScript security signal javascript.xray.serialize-environment in this repository.

Contextual assessment: The cited expression chooses production or development webpack mode from an environment variable. In this tooling file it affects bundling behavior and does not establish runtime exfiltration.

Impact: none · Exploitability: unlikely

Developer action: none

Scanner
javascript-analysis webcrack-2.16.0_js-x-ray-16.0.0_signatures-1_literals-1
Rule
javascript.xray.serialize-environment
File role
tooling
Source
webpack.config.cjs:5

Coverage and limitations

JavaScript coverage

Unresolved JavaScript stages

Tools

Limitations

Technical scan identity