What this review found
No material or immediate-danger item was identified.
Minor cautions
Dependency advisory GHSA-p9ff-h696-f583 applies
Minor caution · low confidence
A security scanner flagged a dependency with a known vulnerability, but the specific package was not identified. Many dependencies in this project are build tools that don't run for end users, and the extension ships pre-built files. Without knowing which package is affected, it's unclear whether this vulnerability actually matters for users.
Technical evidence
Scanner reason: OSV-Scanner matched advisory GHSA-p9ff-h696-f583 to a dependency declared by this repository.
Contextual assessment: OSV-scanner matched a high-severity advisory (GHSA-p9ff-h696-f583) against a dependency in this lockfile, but the affected package name and version were removed from the scanner output. The lockfile contains both production dependencies (diff, fast-xml-parser, handlebars, react, react-dom, sillytavern-utils-lib, zod) and numerous dev-only build tools (vite, vitest, babel, sass, jsdom, etc.). This SillyTavern extension ships built artifacts (dist/index.js, dist/style.css per the manifest), so dev dependencies do not reach end users at runtime. Without identifying the specific affected package, runtime reachability and attacker-controlled input paths cannot be confirmed. The extension operates in a browser context within SillyTavern, limiting the attack surface for most server-side dependency vulnerabilities.
Impact: low · Exploitability: unlikely
Developer action: Run an updated dependency audit with package names visible, identify whether the affected package is a production or dev dependency, and upgrade if a patched version is available.
- Scanner
- osv-scanner 2.4.0
- Rule
- GHSA-p9ff-h696-f583
- File role
- production
- Source
- package-lock.json
Dependency advisory GHSA-5xrq-8626-4rwp applies
Minor caution · low confidence
A scanner found a critical vulnerability in a dependency, but the specific package wasn't identified. This project includes many build-only tools that never run for end users, and ships pre-built files. Without knowing which package is affected, the actual danger to users cannot be confirmed.
Technical evidence
Scanner reason: OSV-Scanner matched advisory GHSA-5xrq-8626-4rwp to a dependency declared by this repository.
Contextual assessment: OSV-scanner matched a critical-severity advisory (GHSA-5xrq-8626-4rwp) against a dependency in this lockfile, but the affected package name and version were removed from the scanner output. The lockfile mixes production and dev dependencies, with the extension shipping only built artifacts per its manifest. Critical advisories in dev-only build tools (e.g., vite, esbuild, jsdom) have no runtime reachability for end users. For production dependencies, the affected package and vulnerable code path cannot be identified from the supplied evidence, so runtime reachability and attacker input control remain unconfirmed. The browser-extension context further limits exploitability of many server-side advisory patterns.
Impact: low · Exploitability: unlikely
Developer action: Run an updated dependency audit with package names visible, determine whether the affected package is production or dev-only, and upgrade to a patched version if available. Prioritize this candidate due to its critical scanner severity.
- Scanner
- osv-scanner 2.4.0
- Rule
- GHSA-5xrq-8626-4rwp
- File role
- production
- Source
- package-lock.json
Dependency advisory GHSA-v6wh-96g9-6wx3 applies
Minor caution · low confidence
A scanner flagged a medium-severity vulnerability in a dependency, but the specific package wasn't identified. Since many dependencies are build tools that don't run for users, the actual risk is unclear.
Technical evidence
Scanner reason: OSV-Scanner matched advisory GHSA-v6wh-96g9-6wx3 to a dependency declared by this repository.
Contextual assessment: OSV-scanner matched a medium-severity advisory (GHSA-v6wh-96g9-6wx3) against a dependency in this lockfile, but the affected package name and version were removed. The lockfile contains both production and dev dependencies, and the extension ships built artifacts. Without identifying the affected package, runtime reachability and attacker-controlled input cannot be determined. Medium-severity advisories in dev-only build tools have no end-user impact.
Impact: low · Exploitability: unlikely
Developer action: Run an updated dependency audit with package names visible and upgrade affected packages if patched versions are available.
- Scanner
- osv-scanner 2.4.0
- Rule
- GHSA-v6wh-96g9-6wx3
- File role
- production
- Source
- package-lock.json
Dependency advisory GHSA-4x5r-pxfx-6jf8 applies
Minor caution · low confidence
A scanner found a low-severity vulnerability in a dependency, but the specific package wasn't identified. Low-severity issues typically have minimal impact, and many dependencies are build tools that don't affect users.
Technical evidence
Scanner reason: OSV-Scanner matched advisory GHSA-4x5r-pxfx-6jf8 to a dependency declared by this repository.
Contextual assessment: OSV-scanner matched a low-severity advisory (GHSA-4x5r-pxfx-6jf8) against a dependency in this lockfile, but the affected package name and version were removed. Low-severity advisories typically have limited concrete impact. The extension ships built artifacts, and many lockfile entries are dev-only build tools. Without package identification, runtime reachability cannot be confirmed.
Impact: low · Exploitability: unlikely
Developer action: Run an updated dependency audit with package names visible and upgrade affected packages if convenient.
- Scanner
- osv-scanner 2.4.0
- Rule
- GHSA-4x5r-pxfx-6jf8
- File role
- production
- Source
- package-lock.json
Dependency advisory GHSA-73rr-hh4g-fpgx applies
Minor caution · low confidence
A scanner found a low-severity vulnerability in a dependency, but the specific package wasn't identified. Low-severity issues typically have minimal impact, and many dependencies are build tools that don't affect users.
Technical evidence
Scanner reason: OSV-Scanner matched advisory GHSA-73rr-hh4g-fpgx to a dependency declared by this repository.
Contextual assessment: OSV-scanner matched a low-severity advisory (GHSA-73rr-hh4g-fpgx) against a dependency in this lockfile, but the affected package name and version were removed. Low-severity advisories typically have limited concrete impact. The extension ships built artifacts, and many lockfile entries are dev-only build tools. Without package identification, runtime reachability cannot be confirmed.
Impact: low · Exploitability: unlikely
Developer action: Run an updated dependency audit with package names visible and upgrade affected packages if convenient.
- Scanner
- osv-scanner 2.4.0
- Rule
- GHSA-73rr-hh4g-fpgx
- File role
- production
- Source
- package-lock.json
Dependency advisory GHSA-jp2q-39xq-3w4g applies
Minor caution · low confidence
A scanner flagged a medium-severity vulnerability in a dependency, but the specific package wasn't identified. Since many dependencies are build tools that don't run for users, the actual risk is unclear.
Technical evidence
Scanner reason: OSV-Scanner matched advisory GHSA-jp2q-39xq-3w4g to a dependency declared by this repository.
Contextual assessment: OSV-scanner matched a medium-severity advisory (GHSA-jp2q-39xq-3w4g) against a dependency in this lockfile, but the affected package name and version were removed. The lockfile contains both production and dev dependencies, and the extension ships built artifacts. Without identifying the affected package, runtime reachability and attacker-controlled input cannot be determined.
Impact: low · Exploitability: unlikely
Developer action: Run an updated dependency audit with package names visible and upgrade affected packages if patched versions are available.
- Scanner
- osv-scanner 2.4.0
- Rule
- GHSA-jp2q-39xq-3w4g
- File role
- production
- Source
- package-lock.json
Dependency advisory GHSA-7rx3-28cr-v5wh applies
Minor caution · low confidence
A scanner flagged a medium-severity vulnerability in a dependency, but the specific package wasn't identified. Since many dependencies are build tools that don't run for users, the actual risk is unclear.
Technical evidence
Scanner reason: OSV-Scanner matched advisory GHSA-7rx3-28cr-v5wh to a dependency declared by this repository.
Contextual assessment: OSV-scanner matched a medium-severity advisory (GHSA-7rx3-28cr-v5wh) against a dependency in this lockfile, but the affected package name and version were removed. The lockfile contains both production and dev dependencies, and the extension ships built artifacts. Without identifying the affected package, runtime reachability and attacker-controlled input cannot be determined.
Impact: low · Exploitability: unlikely
Developer action: Run an updated dependency audit with package names visible and upgrade affected packages if patched versions are available.
- Scanner
- osv-scanner 2.4.0
- Rule
- GHSA-7rx3-28cr-v5wh
- File role
- production
- Source
- package-lock.json
Dependency advisory GHSA-jmr7-xgp7-cmfj applies
Minor caution · low confidence
A scanner flagged a dependency with a high-severity known vulnerability, but the specific package was not identified. Many dependencies are build tools that don't run for end users, and the extension ships pre-built files. Without knowing which package is affected, the actual risk to users is unclear.
Technical evidence
Scanner reason: OSV-Scanner matched advisory GHSA-jmr7-xgp7-cmfj to a dependency declared by this repository.
Contextual assessment: OSV-scanner matched a high-severity advisory (GHSA-jmr7-xgp7-cmfj) against a dependency in this lockfile, but the affected package name and version were removed. The lockfile contains both production dependencies and numerous dev-only build tools. This SillyTavern extension ships built artifacts (dist/index.js, dist/style.css per the manifest), so dev dependencies do not reach end users at runtime. Without identifying the specific affected package, runtime reachability and attacker-controlled input paths cannot be confirmed.
Impact: low · Exploitability: unlikely
Developer action: Run an updated dependency audit with package names visible, determine whether the affected package is production or dev-only, and upgrade to a patched version if available.
- Scanner
- osv-scanner 2.4.0
- Rule
- GHSA-jmr7-xgp7-cmfj
- File role
- production
- Source
- package-lock.json
Dependency advisory GHSA-8gc5-j5rx-235r applies
Minor caution · medium confidence
A security scanner found a known vulnerability in one of the project's dependencies. However, this project builds its code into a single file before shipping, and many of its dependencies are only used during development, not included in what users actually install. Without knowing exactly which dependency is affected, it is unclear whether this vulnerability reaches end users at all.
Technical evidence
Scanner reason: OSV-Scanner matched advisory GHSA-8gc5-j5rx-235r to a dependency declared by this repository.
Contextual assessment: OSV-scanner matched a high-severity advisory in this package-lock.json. The lock file shows this is a build project that ships a bundled artifact (dist/index.js per the manifest). Many visible packages in the lock file are marked dev:true (Babel, esbuild, csstools, etc.) and are not included in the shipped extension. The scanner removed package details, so the specific affected package and whether it is a production or dev-only dependency cannot be confirmed. If the advisory affects a dev-only build tool, it has no runtime impact on end users. If it affects a production dependency bundled into the extension, runtime reachability depends on whether the vulnerable code path is included in the bundle and whether attacker-controlled input reaches it. Advisory severity alone does not establish immediate danger.
Impact: low · Exploitability: unlikely
Developer action: Update the affected dependency to a patched version when feasible, particularly if it is a production dependency. Run an audit with package details visible to identify which specific package is affected and whether it is shipped in the bundle.
- Scanner
- osv-scanner 2.4.0
- Rule
- GHSA-8gc5-j5rx-235r
- File role
- production
- Source
- package-lock.json
Dependency advisory GHSA-9cx6-37pm-9jff applies
Minor caution · medium confidence
A security scanner found a known vulnerability in one of the project's dependencies. Since this project bundles its code before shipping and many dependencies are only used during development, it is unclear whether this vulnerability affects what users actually install.
Technical evidence
Scanner reason: OSV-Scanner matched advisory GHSA-9cx6-37pm-9jff to a dependency declared by this repository.
Contextual assessment: OSV-scanner matched a high-severity advisory in this package-lock.json. The project ships as a Vite-built bundle (dist/index.js), and the lock file shows numerous dev-only dependencies that are not included in the shipped artifact. The scanner removed package details, preventing confirmation of whether the affected package is a production dependency bundled into the extension or a dev-only build tool. Without identifying the specific package, runtime reachability and attacker input paths cannot be assessed. Advisory severity alone is not an immediate-danger conclusion.
Impact: low · Exploitability: unlikely
Developer action: Update the affected dependency to a patched version when feasible. Run an audit with package details visible to identify the specific affected package and whether it ships in the bundle.
- Scanner
- osv-scanner 2.4.0
- Rule
- GHSA-9cx6-37pm-9jff
- File role
- production
- Source
- package-lock.json
Dependency advisory GHSA-37qj-frw5-hhjh applies
Minor caution · medium confidence
A security scanner found a known vulnerability in one of the project's dependencies. Because the project packages its code into a single file before distribution and many dependencies are development-only, it is uncertain whether this vulnerability reaches users.
Technical evidence
Scanner reason: OSV-Scanner matched advisory GHSA-37qj-frw5-hhjh to a dependency declared by this repository.
Contextual assessment: OSV-scanner matched a high-severity advisory in this package-lock.json. The extension manifest indicates the shipped artifact is a pre-built bundle (dist/index.js, dist/style.css), meaning dev dependencies in the lock file are not distributed to end users. The scanner removed package details, so the specific affected package cannot be identified. If the advisory targets a dev-only build tool, there is no end-user impact. If it targets a production dependency, the vulnerable code path may or may not be reachable in the bundled output. Without the package identity, a definitive reachability assessment is not possible.
Impact: low · Exploitability: unlikely
Developer action: Update the affected dependency to a patched version when feasible. Identify the specific affected package to determine whether it is shipped in the bundle.
- Scanner
- osv-scanner 2.4.0
- Rule
- GHSA-37qj-frw5-hhjh
- File role
- production
- Source
- package-lock.json
Dependency advisory GHSA-m7jm-9gc2-mpf2 applies
Minor caution · medium confidence
A security scanner found a critical vulnerability in one of the project's dependencies. However, this project bundles its code before shipping, and many dependencies are only used during development. Without knowing which specific dependency is affected, it is unclear whether this vulnerability actually reaches users.
Technical evidence
Scanner reason: OSV-Scanner matched advisory GHSA-m7jm-9gc2-mpf2 to a dependency declared by this repository.
Contextual assessment: OSV-scanner matched a critical-severity advisory in this package-lock.json. Despite the critical scanner rating, the project ships a Vite-built bundle rather than raw node_modules, and the lock file shows many dev-only dependencies that are excluded from the shipped artifact. The scanner removed package details, so the specific affected package cannot be confirmed. If this advisory targets a dev-only build tool such as Vite or esbuild, there is no runtime impact on end users. If it targets a production dependency, runtime reachability in the bundle and attacker-controlled input paths would need further analysis. Advisory severity alone does not establish immediate danger without confirming the affected package is shipped and its vulnerable code is reachable.
Impact: low · Exploitability: unlikely
Developer action: Prioritize updating the affected dependency to a patched version. Run an audit with package details visible to identify the specific affected package and confirm whether it is a production dependency included in the shipped bundle.
- Scanner
- osv-scanner 2.4.0
- Rule
- GHSA-m7jm-9gc2-mpf2
- File role
- production
- Source
- package-lock.json
Dependency advisory GHSA-4w7w-66w2-5vf9 applies
Minor caution · medium confidence
A security scanner found a medium-severity vulnerability in one of the project's dependencies. Since the project bundles its code before shipping and many dependencies are development-only, it is unclear whether this affects users.
Technical evidence
Scanner reason: OSV-Scanner matched advisory GHSA-4w7w-66w2-5vf9 to a dependency declared by this repository.
Contextual assessment: OSV-scanner matched a medium-severity advisory in this package-lock.json. The project distributes a pre-built bundle, and the lock file contains many dev-only dependencies not included in the shipped extension. The scanner removed package details, preventing identification of the specific affected package. Without knowing whether the advisory targets a production or dev-only dependency, runtime reachability cannot be determined. Medium-severity advisories in dev-only build tools have no end-user impact.
Impact: low · Exploitability: unlikely
Developer action: Update the affected dependency to a patched version when feasible. Identify the specific affected package to determine whether it ships in the bundle.
- Scanner
- osv-scanner 2.4.0
- Rule
- GHSA-4w7w-66w2-5vf9
- File role
- production
- Source
- package-lock.json
Dependency advisory GHSA-hmw2-7cc7-3qxx applies
Minor caution · medium confidence
A security scanner found a known vulnerability in one of the project's dependencies. Because the project bundles its code before shipping and many dependencies are development-only, it is uncertain whether this vulnerability reaches users.
Technical evidence
Scanner reason: OSV-Scanner matched advisory GHSA-hmw2-7cc7-3qxx to a dependency declared by this repository.
Contextual assessment: OSV-scanner matched a high-severity advisory in this package-lock.json. The extension ships as a Vite-built bundle, and the lock file shows numerous dev-only dependencies excluded from the shipped artifact. The scanner removed package details, so the specific affected package cannot be identified. If the advisory targets a dev-only build tool, there is no end-user impact. If it targets a production dependency bundled into the extension, runtime reachability depends on whether the vulnerable code path is included and reachable. Without the package identity, a definitive assessment is not possible.
Impact: low · Exploitability: unlikely
Developer action: Update the affected dependency to a patched version when feasible. Identify the specific affected package to determine whether it ships in the bundle.
- Scanner
- osv-scanner 2.4.0
- Rule
- GHSA-hmw2-7cc7-3qxx
- File role
- production
- Source
- package-lock.json
Dependency advisory GHSA-wf6x-7x77-mvgw applies
Minor caution · medium confidence
A security scanner found a known vulnerability in one of the project's dependencies. Since the project bundles its code before shipping and many dependencies are development-only, it is unclear whether this vulnerability affects users.
Technical evidence
Scanner reason: OSV-Scanner matched advisory GHSA-wf6x-7x77-mvgw to a dependency declared by this repository.
Contextual assessment: OSV-scanner matched a high-severity advisory in this package-lock.json. The project distributes a pre-built bundle per the manifest, and the lock file contains many dev-only dependencies not shipped to end users. The scanner removed package details, preventing identification of the specific affected package. Without knowing whether the advisory targets a production or dev-only dependency, runtime reachability in the shipped extension cannot be determined. Advisory severity alone does not establish immediate danger.
Impact: low · Exploitability: unlikely
Developer action: Update the affected dependency to a patched version when feasible. Identify the specific affected package to determine whether it ships in the bundle.
- Scanner
- osv-scanner 2.4.0
- Rule
- GHSA-wf6x-7x77-mvgw
- File role
- production
- Source
- package-lock.json
Dependency advisory GHSA-gh4j-gqv2-49f6 applies
Minor caution · medium confidence
A security scanner found a medium-severity vulnerability in one of the project's dependencies. Because the project bundles its code before shipping and many dependencies are development-only, it is uncertain whether this vulnerability reaches users.
Technical evidence
Scanner reason: OSV-Scanner matched advisory GHSA-gh4j-gqv2-49f6 to a dependency declared by this repository.
Contextual assessment: OSV-scanner matched a medium-severity advisory in this package-lock.json. The extension ships as a Vite-built bundle, and the lock file shows many dev-only dependencies excluded from the shipped artifact. The scanner removed package details, so the specific affected package cannot be identified. If the advisory targets a dev-only build tool, there is no end-user impact. If it targets a production dependency, runtime reachability depends on whether the vulnerable code path is included in the bundle. Without the package identity, a definitive assessment is not possible.
Impact: low · Exploitability: unlikely
Developer action: Update the affected dependency to a patched version when feasible. Identify the specific affected package to determine whether it ships in the bundle.
- Scanner
- osv-scanner 2.4.0
- Rule
- GHSA-gh4j-gqv2-49f6
- File role
- production
- Source
- package-lock.json
Dependency advisory GHSA-2w6w-674q-4c4q applies
Minor caution · medium confidence
The flagged critical issue is almost certainly in a build tool used only during development, not in the code that actually ships to users. End users installing this extension are not exposed to this vulnerability.
Technical evidence
Scanner reason: OSV-Scanner matched advisory GHSA-2w6w-674q-4c4q to a dependency declared by this repository.
Contextual assessment: This critical advisory most likely corresponds to a build-tool dependency such as vite, which is declared as a devDependency and is not bundled into the shipped extension output. The extension ships only dist/index.js and dist/style.css to end users. Build-tool vulnerabilities affecting the local development server do not create runtime attack surface for SillyTavern users who install the extension. Without the specific package name from the scanner, runtime reachability cannot be confirmed, but the project structure strongly indicates this is a development-only dependency.
Impact: none · Exploitability: unlikely
Developer action: Update the affected devDependency to the patched version as a best practice to protect the development environment.
- Scanner
- osv-scanner 2.4.0
- Rule
- GHSA-2w6w-674q-4c4q
- File role
- production
- Source
- package-lock.json
Dependency advisory GHSA-xjpj-3mr7-gcpf applies
Minor caution · medium confidence
The flagged issue is probably in a development tool that does not ship with the extension. Users who install the extension are not affected.
Technical evidence
Scanner reason: OSV-Scanner matched advisory GHSA-xjpj-3mr7-gcpf to a dependency declared by this repository.
Contextual assessment: This high-severity advisory likely affects a build-toolchain dependency in the vite, vitest, or related ecosystem, all of which are devDependencies. These packages are not included in the bundled dist/index.js that ships to SillyTavern users. The extension runs in the browser within SillyTavern's context and has no server-side component, so server-side build-tool vulnerabilities are not reachable at runtime.
Impact: none · Exploitability: unlikely
Developer action: Update the affected dependency to the patched version during the next build cycle.
- Scanner
- osv-scanner 2.4.0
- Rule
- GHSA-xjpj-3mr7-gcpf
- File role
- production
- Source
- package-lock.json
Dependency advisory GHSA-v56q-mh7h-f735 applies
Minor caution · medium confidence
The flagged issue is likely in a development-only tool that is not included in the extension users install.
Technical evidence
Scanner reason: OSV-Scanner matched advisory GHSA-v56q-mh7h-f735 to a dependency declared by this repository.
Contextual assessment: This high-severity advisory is most likely associated with a devDependency in the build toolchain. The shipped extension artifact is a browser bundle that excludes devDependencies. Without the specific package identification from the scanner, exact runtime reachability cannot be determined, but the project's dependency structure indicates the vulnerable code does not reach end users.
Impact: none · Exploitability: unlikely
Developer action: Update the affected dependency to the patched version.
- Scanner
- osv-scanner 2.4.0
- Rule
- GHSA-v56q-mh7h-f735
- File role
- production
- Source
- package-lock.json
Dependency advisory GHSA-6g55-p6wh-862q applies
Minor caution · medium confidence
The flagged issue is probably in a tool used only for building the extension, not in the code users receive.
Technical evidence
Scanner reason: OSV-Scanner matched advisory GHSA-6g55-p6wh-862q to a dependency declared by this repository.
Contextual assessment: This high-severity advisory likely targets a build-tool or transitive devDependency. The extension is a browser-based SillyTavern add-on that ships only the bundled output, not the full dependency tree. DevDependencies and their transitive dependencies are excluded from the shipped bundle, so the vulnerable code is not present in the end-user runtime.
Impact: none · Exploitability: unlikely
Developer action: Update the affected dependency to the patched version.
- Scanner
- osv-scanner 2.4.0
- Rule
- GHSA-6g55-p6wh-862q
- File role
- production
- Source
- package-lock.json
Dependency advisory GHSA-r28c-9q8g-f849 applies
Minor caution · medium confidence
The flagged issue is likely in a development tool that does not ship to users.
Technical evidence
Scanner reason: OSV-Scanner matched advisory GHSA-r28c-9q8g-f849 to a dependency declared by this repository.
Contextual assessment: This high-severity advisory is most likely for a build-toolchain dependency declared under devDependencies. The shipped extension bundle does not include devDependencies. The scanner removed specific package details, preventing definitive identification, but the project structure and the concentration of advisories in the vite and vitest ecosystem support the conclusion that this is a development-only dependency.
Impact: none · Exploitability: unlikely
Developer action: Update the affected dependency to the patched version.
- Scanner
- osv-scanner 2.4.0
- Rule
- GHSA-r28c-9q8g-f849
- File role
- production
- Source
- package-lock.json
Dependency advisory GHSA-xhpv-hc6g-r9c6 applies
Minor caution · low confidence
The flagged issue might be in a library that ships with the extension, but without knowing the exact package, we cannot confirm whether users are affected. The developer should check and update the dependency.
Technical evidence
Scanner reason: OSV-Scanner matched advisory GHSA-xhpv-hc6g-r9c6 to a dependency declared by this repository.
Contextual assessment: This high-severity advisory could potentially affect either a devDependency or a production dependency. If it affects a production dependency such as handlebars or fast-xml-parser, the extension does process LLM-generated content and character data through these libraries. However, the browser extension context limits the impact of many server-side vulnerability classes. Without the specific package name from the scanner, runtime reachability cannot be definitively assessed. The developer should verify which package is affected and whether the vulnerable code path is exercised in the shipped bundle.
Impact: low · Exploitability: unlikely
Developer action: Identify the affected package, update it to the patched version, and verify that the vulnerable code path is not reachable in the shipped bundle.
- Scanner
- osv-scanner 2.4.0
- Rule
- GHSA-xhpv-hc6g-r9c6
- File role
- production
- Source
- package-lock.json
Dependency advisory GHSA-xvcm-6775-5m9r applies
Minor caution · low confidence
The flagged issue may or may not affect the code users receive. The developer should identify the affected package and update it.
Technical evidence
Scanner reason: OSV-Scanner matched advisory GHSA-xvcm-6775-5m9r to a dependency declared by this repository.
Contextual assessment: This high-severity advisory could affect either a build-tool dependency or a production dependency. The scanner removed package details, preventing definitive identification. If the affected package is a devDependency, the vulnerable code does not ship to end users. If it is a production dependency, the browser extension context and the data flows within SillyTavern would need to be examined for runtime reachability. The advisory severity alone does not establish end-user harm.
Impact: low · Exploitability: unlikely
Developer action: Identify the affected package, update it to the patched version, and confirm the vulnerable code is not reachable in the shipped bundle.
- Scanner
- osv-scanner 2.4.0
- Rule
- GHSA-xvcm-6775-5m9r
- File role
- production
- Source
- package-lock.json
Dependency advisory GHSA-3v7f-55p6-f55p applies
Minor caution · medium confidence
The flagged issue is likely in a development tool or its sub-dependency that does not ship with the extension.
Technical evidence
Scanner reason: OSV-Scanner matched advisory GHSA-3v7f-55p6-f55p to a dependency declared by this repository.
Contextual assessment: This medium-severity advisory likely affects a transitive dependency in the build toolchain. Medium-severity advisories in this ecosystem commonly relate to development tools or their transitive dependencies, which are not included in the shipped browser extension bundle. The extension ships only the compiled dist output to end users.
Impact: none · Exploitability: unlikely
Developer action: Update the affected dependency to the patched version during the next maintenance cycle.
- Scanner
- osv-scanner 2.4.0
- Rule
- GHSA-3v7f-55p6-f55p
- File role
- production
- Source
- package-lock.json
Dependency advisory GHSA-3mfm-83xf-c92r applies
Minor caution · low confidence
A security scanner flagged a dependency in this project's build configuration. However, the specific package was not identified, and many dependencies in this file are only used during development, not in the final product users install. Without knowing which package is affected, it is unclear whether this poses any real risk to users.
Technical evidence
Scanner reason: OSV-Scanner matched advisory GHSA-3mfm-83xf-c92r to a dependency declared by this repository.
Contextual assessment: OSV-scanner matched advisory GHSA-3mfm-83xf-c92r against a dependency in the lockfile, but package details were removed so the specific affected package and version cannot be confirmed. The lockfile includes many dev-only build-tool dependencies (babel, esbuild, vite, vitest) that are not shipped in the compiled extension artifact (dist/index.js, dist/style.css). Without knowing which package matched, runtime reachability and attacker-controlled input paths cannot be determined. The advisory severity alone does not establish concrete user harm in this extension context.
Impact: low · Exploitability: unlikely
Developer action: Run an updated dependency audit with package details visible, identify the specific affected package, and update it if it is a production dependency or if the vulnerable code path is reachable.
- Scanner
- osv-scanner 2.4.0
- Rule
- GHSA-3mfm-83xf-c92r
- File role
- production
- Source
- package-lock.json
Dependency advisory GHSA-mw96-cpmx-2vgc applies
Minor caution · low confidence
A security scanner flagged a dependency in this project. The specific package was not identified, so it is unclear whether this affects the final product or only development tools. The risk to end users is uncertain but likely low.
Technical evidence
Scanner reason: OSV-Scanner matched advisory GHSA-mw96-cpmx-2vgc to a dependency declared by this repository.
Contextual assessment: OSV-scanner matched advisory GHSA-mw96-cpmx-2vgc against a dependency in the lockfile, but package details were removed. The lockfile contains both production dependencies (diff, fast-xml-parser, handlebars, react, react-dom, sillytavern-utils-lib, zod) and numerous dev-only dependencies. The shipped extension is a compiled bundle, so dev dependencies do not reach end users. Without the specific package identity, version, and whether the vulnerable code is bundled into the production output, concrete user harm cannot be established.
Impact: low · Exploitability: unlikely
Developer action: Run an updated dependency audit with package details visible, identify the specific affected package, and update it if it is a production dependency or if the vulnerable code path is reachable.
- Scanner
- osv-scanner 2.4.0
- Rule
- GHSA-mw96-cpmx-2vgc
- File role
- production
- Source
- package-lock.json
Dependency advisory GHSA-v2wj-q39q-566r applies
Minor caution · low confidence
A security scanner flagged a dependency in this project. The specific package was not identified, so it is unclear whether this affects the final product or only development tools. The risk to end users is uncertain but likely low.
Technical evidence
Scanner reason: OSV-Scanner matched advisory GHSA-v2wj-q39q-566r to a dependency declared by this repository.
Contextual assessment: OSV-scanner matched advisory GHSA-v2wj-q39q-566r against a dependency in the lockfile, but package details were removed. The extension ships as compiled dist artifacts, and the lockfile includes many dev-only toolchain dependencies that do not ship to end users. Without the specific package and version, runtime reachability of the vulnerable code in the production bundle cannot be determined.
Impact: low · Exploitability: unlikely
Developer action: Run an updated dependency audit with package details visible, identify the specific affected package, and update it if it is a production dependency or if the vulnerable code path is reachable.
- Scanner
- osv-scanner 2.4.0
- Rule
- GHSA-v2wj-q39q-566r
- File role
- production
- Source
- package-lock.json
Dependency advisory GHSA-fj3w-jwp8-x2g3 applies
Minor caution · low confidence
A security scanner flagged a low-severity issue in a dependency. The specific package was not identified, and the severity is low. The risk to end users is likely minimal.
Technical evidence
Scanner reason: OSV-Scanner matched advisory GHSA-fj3w-jwp8-x2g3 to a dependency declared by this repository.
Contextual assessment: OSV-scanner matched low-severity advisory GHSA-fj3w-jwp8-x2g3 against a dependency in the lockfile, but package details were removed. The low scanner severity and the absence of package identity mean concrete user harm cannot be established. The extension ships compiled artifacts, and many lockfile entries are dev-only dependencies.
Impact: low · Exploitability: unlikely
Developer action: Run an updated dependency audit with package details visible and update the affected package if feasible.
- Scanner
- osv-scanner 2.4.0
- Rule
- GHSA-fj3w-jwp8-x2g3
- File role
- production
- Source
- package-lock.json
Dependency advisory GHSA-qx2v-qp2m-jg93 applies
Minor caution · low confidence
A security scanner flagged a medium-severity issue in a dependency. The specific package was not identified, so it is unclear whether this affects the final product. The risk to end users is uncertain but likely low.
Technical evidence
Scanner reason: OSV-Scanner matched advisory GHSA-qx2v-qp2m-jg93 to a dependency declared by this repository.
Contextual assessment: OSV-scanner matched medium-severity advisory GHSA-qx2v-qp2m-jg93 against a dependency in the lockfile, but package details were removed. Without the specific package and version, it is impossible to determine whether the vulnerable code is a production dependency bundled into the shipped extension or a dev-only dependency. Runtime reachability and attacker input paths cannot be assessed.
Impact: low · Exploitability: unlikely
Developer action: Run an updated dependency audit with package details visible, identify the specific affected package, and update it if it is a production dependency or if the vulnerable code path is reachable.
- Scanner
- osv-scanner 2.4.0
- Rule
- GHSA-qx2v-qp2m-jg93
- File role
- production
- Source
- package-lock.json
Dependency advisory GHSA-fxqj-rqcc-2cmp applies
Minor caution · low confidence
A security scanner flagged a medium-severity issue in a dependency. The specific package was not identified, so it is unclear whether this affects the final product. The risk to end users is uncertain but likely low.
Technical evidence
Scanner reason: OSV-Scanner matched advisory GHSA-fxqj-rqcc-2cmp to a dependency declared by this repository.
Contextual assessment: OSV-scanner matched medium-severity advisory GHSA-fxqj-rqcc-2cmp against a dependency in the lockfile, but package details were removed. Without the specific package identity and version, runtime reachability in the production bundle cannot be determined. The extension ships compiled artifacts, and many lockfile entries are dev-only dependencies that do not reach end users.
Impact: low · Exploitability: unlikely
Developer action: Run an updated dependency audit with package details visible, identify the specific affected package, and update it if it is a production dependency or if the vulnerable code path is reachable.
- Scanner
- osv-scanner 2.4.0
- Rule
- GHSA-fxqj-rqcc-2cmp
- File role
- production
- Source
- package-lock.json
Dependency advisory GHSA-96hv-2xvq-fx4p applies
Minor caution · low confidence
A security scanner flagged a high-severity issue in a dependency. However, the specific package was not identified, and many dependencies in this file are only used during development. Without knowing which package is affected, the real risk to users is uncertain.
Technical evidence
Scanner reason: OSV-Scanner matched advisory GHSA-96hv-2xvq-fx4p to a dependency declared by this repository.
Contextual assessment: OSV-scanner matched high-severity advisory GHSA-96hv-2xvq-fx4p against a dependency in the lockfile, but package details were removed. Despite the high scanner severity, without the specific package and version, it cannot be determined whether the vulnerable code is bundled into the shipped extension or is a dev-only dependency. Advisory severity alone does not establish concrete user harm in this extension context.
Impact: low · Exploitability: unlikely
Developer action: Run an updated dependency audit with package details visible, identify the specific affected package, and update it if it is a production dependency or if the vulnerable code path is reachable.
- Scanner
- osv-scanner 2.4.0
- Rule
- GHSA-96hv-2xvq-fx4p
- File role
- production
- Source
- package-lock.json
Dependency advisory GHSA-442j-39wm-28r2 applies
Minor caution · low confidence
A security scanner flagged a low-severity issue in a dependency. The specific package was not identified, and the severity is low. The risk to end users is likely minimal.
Technical evidence
Scanner reason: OSV-Scanner matched advisory GHSA-442j-39wm-28r2 to a dependency declared by this repository.
Contextual assessment: OSV-scanner matched low-severity advisory GHSA-442j-39wm-28r2 against a dependency in the lockfile, but package details were removed. The low scanner severity and the absence of package identity mean concrete user harm cannot be established. The extension ships compiled artifacts, and many lockfile entries are dev-only dependencies.
Impact: low · Exploitability: unlikely
Developer action: Run an updated dependency audit with package details visible and update the affected package if feasible.
- Scanner
- osv-scanner 2.4.0
- Rule
- GHSA-442j-39wm-28r2
- File role
- production
- Source
- package-lock.json
Dependency advisory GHSA-58qx-3vcg-4xpx applies
Minor caution · medium confidence
A security scanner found a known issue in a package used by this project. The package is most likely a development tool that is not included in the actual extension users install, so it should not affect people using the extension.
Technical evidence
Scanner reason: OSV-Scanner matched advisory GHSA-58qx-3vcg-4xpx to a dependency declared by this repository.
Contextual assessment: OSV-scanner matched a medium-severity advisory against a dependency declared in the lockfile. The project ships a Vite-bundled dist/index.js and dist/style.css as its SillyTavern extension artifact; build-time and test-time devDependencies are not included in the shipped output. The advisory most likely corresponds to a build-tool or transitive dev dependency that has no runtime reachability in the installed extension. Even if it touched a production dependency, the extension executes in a browser context within SillyTavern with limited attacker-controlled input paths to the vulnerable code. No concrete end-user harm is demonstrated by the available evidence.
Impact: low · Exploitability: unlikely
Developer action: Update the flagged dependency to a patched version when convenient to keep the development environment current.
- Scanner
- osv-scanner 2.4.0
- Rule
- GHSA-58qx-3vcg-4xpx
- File role
- production
- Source
- package-lock.json
Dependency advisory GHSA-c2c7-rcm5-vvqj applies
Minor caution · medium confidence
A scanner flagged a serious-sounding issue in a package, but the package is most likely a build tool that stays on the developer's machine and is not part of what users install. The risk to extension users is low.
Technical evidence
Scanner reason: OSV-Scanner matched advisory GHSA-c2c7-rcm5-vvqj to a dependency declared by this repository.
Contextual assessment: OSV-scanner matched a high-severity advisory against a dependency in the lockfile. The project manifest shows the extension artifact is a Vite production build (dist/index.js); devDependencies such as Vite, Vitest, jsdom, and their transitive dependencies are not shipped to end users. High-severity advisories in build tooling commonly affect the local dev server or build pipeline rather than the bundled output. Without the full lockfile showing the exact flagged package and version, the most probable target is a build-tool dependency with no runtime reachability in the installed extension. No attacker-controlled input path to the vulnerable code in a deployed context is evident.
Impact: low · Exploitability: unlikely
Developer action: Update the flagged dependency to a patched version to maintain a secure development environment.
- Scanner
- osv-scanner 2.4.0
- Rule
- GHSA-c2c7-rcm5-vvqj
- File role
- production
- Source
- package-lock.json
Dependency advisory GHSA-2qvq-rjwj-gvw9 applies
Minor caution · medium confidence
A scanner found a moderate issue in a package used during development. Since the package is likely not included in the final extension, it should not impact users who install it.
Technical evidence
Scanner reason: OSV-Scanner matched advisory GHSA-2qvq-rjwj-gvw9 to a dependency declared by this repository.
Contextual assessment: OSV-scanner matched a medium-severity advisory against a dependency in the lockfile. The shipped extension consists of a Vite-bundled JavaScript file and CSS; development and test dependencies are excluded from the artifact. The advisory likely targets a transitive dev dependency or build tool with no code path reachable at runtime in the installed extension. The browser-based execution context within SillyTavern further limits the attack surface for most dependency-class vulnerabilities. No concrete user harm is demonstrated.
Impact: low · Exploitability: unlikely
Developer action: Update the flagged dependency to a patched version when convenient.
- Scanner
- osv-scanner 2.4.0
- Rule
- GHSA-2qvq-rjwj-gvw9
- File role
- production
- Source
- package-lock.json
Dependency advisory GHSA-fx2h-pf6j-xcff applies
Minor caution · medium confidence
A scanner flagged a serious issue in a package, but it is most likely a development tool that does not ship with the extension. The risk to people using the extension is low.
Technical evidence
Scanner reason: OSV-Scanner matched advisory GHSA-fx2h-pf6j-xcff to a dependency declared by this repository.
Contextual assessment: OSV-scanner matched a high-severity advisory against a dependency in the lockfile. The project structure indicates the extension is distributed as a Vite production build, meaning devDependencies and their transitive packages are not present in the installed extension. High-severity advisories commonly associated with build tooling affect the development server or build pipeline, not the bundled output served to SillyTavern users. The available evidence does not show attacker-controlled input reaching vulnerable code in a deployed context. No concrete end-user harm is demonstrated.
Impact: low · Exploitability: unlikely
Developer action: Update the flagged dependency to a patched version to keep the build toolchain secure.
- Scanner
- osv-scanner 2.4.0
- Rule
- GHSA-fx2h-pf6j-xcff
- File role
- production
- Source
- package-lock.json
Expected scanner matches (0)
None.