TavernKeeper Scan Report

bmen25124/SillyTavern-Character-Creator

Commit 8ddf5ba Reviewed

No material or immediate-danger concern was identified in this review.

This advisory report describes what the named tools and contextual reviewer found at one exact commit. Unknown or unobserved behavior may still exist.

0 immediate danger 0 material 40 low

What this review found

No material or immediate-danger item was identified.

Minor cautions

Dependency advisory GHSA-p9ff-h696-f583 applies

Minor caution · low confidence

A security scanner flagged a dependency with a known vulnerability, but the specific package was not identified. Many dependencies in this project are build tools that don't run for end users, and the extension ships pre-built files. Without knowing which package is affected, it's unclear whether this vulnerability actually matters for users.

Technical evidence

Scanner reason: OSV-Scanner matched advisory GHSA-p9ff-h696-f583 to a dependency declared by this repository.

Contextual assessment: OSV-scanner matched a high-severity advisory (GHSA-p9ff-h696-f583) against a dependency in this lockfile, but the affected package name and version were removed from the scanner output. The lockfile contains both production dependencies (diff, fast-xml-parser, handlebars, react, react-dom, sillytavern-utils-lib, zod) and numerous dev-only build tools (vite, vitest, babel, sass, jsdom, etc.). This SillyTavern extension ships built artifacts (dist/index.js, dist/style.css per the manifest), so dev dependencies do not reach end users at runtime. Without identifying the specific affected package, runtime reachability and attacker-controlled input paths cannot be confirmed. The extension operates in a browser context within SillyTavern, limiting the attack surface for most server-side dependency vulnerabilities.

Impact: low · Exploitability: unlikely

Developer action: Run an updated dependency audit with package names visible, identify whether the affected package is a production or dev dependency, and upgrade if a patched version is available.

Scanner
osv-scanner 2.4.0
Rule
GHSA-p9ff-h696-f583
File role
production
Source
package-lock.json

Dependency advisory GHSA-5xrq-8626-4rwp applies

Minor caution · low confidence

A scanner found a critical vulnerability in a dependency, but the specific package wasn't identified. This project includes many build-only tools that never run for end users, and ships pre-built files. Without knowing which package is affected, the actual danger to users cannot be confirmed.

Technical evidence

Scanner reason: OSV-Scanner matched advisory GHSA-5xrq-8626-4rwp to a dependency declared by this repository.

Contextual assessment: OSV-scanner matched a critical-severity advisory (GHSA-5xrq-8626-4rwp) against a dependency in this lockfile, but the affected package name and version were removed from the scanner output. The lockfile mixes production and dev dependencies, with the extension shipping only built artifacts per its manifest. Critical advisories in dev-only build tools (e.g., vite, esbuild, jsdom) have no runtime reachability for end users. For production dependencies, the affected package and vulnerable code path cannot be identified from the supplied evidence, so runtime reachability and attacker input control remain unconfirmed. The browser-extension context further limits exploitability of many server-side advisory patterns.

Impact: low · Exploitability: unlikely

Developer action: Run an updated dependency audit with package names visible, determine whether the affected package is production or dev-only, and upgrade to a patched version if available. Prioritize this candidate due to its critical scanner severity.

Scanner
osv-scanner 2.4.0
Rule
GHSA-5xrq-8626-4rwp
File role
production
Source
package-lock.json

Dependency advisory GHSA-v6wh-96g9-6wx3 applies

Minor caution · low confidence

A scanner flagged a medium-severity vulnerability in a dependency, but the specific package wasn't identified. Since many dependencies are build tools that don't run for users, the actual risk is unclear.

Technical evidence

Scanner reason: OSV-Scanner matched advisory GHSA-v6wh-96g9-6wx3 to a dependency declared by this repository.

Contextual assessment: OSV-scanner matched a medium-severity advisory (GHSA-v6wh-96g9-6wx3) against a dependency in this lockfile, but the affected package name and version were removed. The lockfile contains both production and dev dependencies, and the extension ships built artifacts. Without identifying the affected package, runtime reachability and attacker-controlled input cannot be determined. Medium-severity advisories in dev-only build tools have no end-user impact.

Impact: low · Exploitability: unlikely

Developer action: Run an updated dependency audit with package names visible and upgrade affected packages if patched versions are available.

Scanner
osv-scanner 2.4.0
Rule
GHSA-v6wh-96g9-6wx3
File role
production
Source
package-lock.json

Dependency advisory GHSA-4x5r-pxfx-6jf8 applies

Minor caution · low confidence

A scanner found a low-severity vulnerability in a dependency, but the specific package wasn't identified. Low-severity issues typically have minimal impact, and many dependencies are build tools that don't affect users.

Technical evidence

Scanner reason: OSV-Scanner matched advisory GHSA-4x5r-pxfx-6jf8 to a dependency declared by this repository.

Contextual assessment: OSV-scanner matched a low-severity advisory (GHSA-4x5r-pxfx-6jf8) against a dependency in this lockfile, but the affected package name and version were removed. Low-severity advisories typically have limited concrete impact. The extension ships built artifacts, and many lockfile entries are dev-only build tools. Without package identification, runtime reachability cannot be confirmed.

Impact: low · Exploitability: unlikely

Developer action: Run an updated dependency audit with package names visible and upgrade affected packages if convenient.

Scanner
osv-scanner 2.4.0
Rule
GHSA-4x5r-pxfx-6jf8
File role
production
Source
package-lock.json

Dependency advisory GHSA-73rr-hh4g-fpgx applies

Minor caution · low confidence

A scanner found a low-severity vulnerability in a dependency, but the specific package wasn't identified. Low-severity issues typically have minimal impact, and many dependencies are build tools that don't affect users.

Technical evidence

Scanner reason: OSV-Scanner matched advisory GHSA-73rr-hh4g-fpgx to a dependency declared by this repository.

Contextual assessment: OSV-scanner matched a low-severity advisory (GHSA-73rr-hh4g-fpgx) against a dependency in this lockfile, but the affected package name and version were removed. Low-severity advisories typically have limited concrete impact. The extension ships built artifacts, and many lockfile entries are dev-only build tools. Without package identification, runtime reachability cannot be confirmed.

Impact: low · Exploitability: unlikely

Developer action: Run an updated dependency audit with package names visible and upgrade affected packages if convenient.

Scanner
osv-scanner 2.4.0
Rule
GHSA-73rr-hh4g-fpgx
File role
production
Source
package-lock.json

Dependency advisory GHSA-jp2q-39xq-3w4g applies

Minor caution · low confidence

A scanner flagged a medium-severity vulnerability in a dependency, but the specific package wasn't identified. Since many dependencies are build tools that don't run for users, the actual risk is unclear.

Technical evidence

Scanner reason: OSV-Scanner matched advisory GHSA-jp2q-39xq-3w4g to a dependency declared by this repository.

Contextual assessment: OSV-scanner matched a medium-severity advisory (GHSA-jp2q-39xq-3w4g) against a dependency in this lockfile, but the affected package name and version were removed. The lockfile contains both production and dev dependencies, and the extension ships built artifacts. Without identifying the affected package, runtime reachability and attacker-controlled input cannot be determined.

Impact: low · Exploitability: unlikely

Developer action: Run an updated dependency audit with package names visible and upgrade affected packages if patched versions are available.

Scanner
osv-scanner 2.4.0
Rule
GHSA-jp2q-39xq-3w4g
File role
production
Source
package-lock.json

Dependency advisory GHSA-7rx3-28cr-v5wh applies

Minor caution · low confidence

A scanner flagged a medium-severity vulnerability in a dependency, but the specific package wasn't identified. Since many dependencies are build tools that don't run for users, the actual risk is unclear.

Technical evidence

Scanner reason: OSV-Scanner matched advisory GHSA-7rx3-28cr-v5wh to a dependency declared by this repository.

Contextual assessment: OSV-scanner matched a medium-severity advisory (GHSA-7rx3-28cr-v5wh) against a dependency in this lockfile, but the affected package name and version were removed. The lockfile contains both production and dev dependencies, and the extension ships built artifacts. Without identifying the affected package, runtime reachability and attacker-controlled input cannot be determined.

Impact: low · Exploitability: unlikely

Developer action: Run an updated dependency audit with package names visible and upgrade affected packages if patched versions are available.

Scanner
osv-scanner 2.4.0
Rule
GHSA-7rx3-28cr-v5wh
File role
production
Source
package-lock.json

Dependency advisory GHSA-jmr7-xgp7-cmfj applies

Minor caution · low confidence

A scanner flagged a dependency with a high-severity known vulnerability, but the specific package was not identified. Many dependencies are build tools that don't run for end users, and the extension ships pre-built files. Without knowing which package is affected, the actual risk to users is unclear.

Technical evidence

Scanner reason: OSV-Scanner matched advisory GHSA-jmr7-xgp7-cmfj to a dependency declared by this repository.

Contextual assessment: OSV-scanner matched a high-severity advisory (GHSA-jmr7-xgp7-cmfj) against a dependency in this lockfile, but the affected package name and version were removed. The lockfile contains both production dependencies and numerous dev-only build tools. This SillyTavern extension ships built artifacts (dist/index.js, dist/style.css per the manifest), so dev dependencies do not reach end users at runtime. Without identifying the specific affected package, runtime reachability and attacker-controlled input paths cannot be confirmed.

Impact: low · Exploitability: unlikely

Developer action: Run an updated dependency audit with package names visible, determine whether the affected package is production or dev-only, and upgrade to a patched version if available.

Scanner
osv-scanner 2.4.0
Rule
GHSA-jmr7-xgp7-cmfj
File role
production
Source
package-lock.json

Dependency advisory GHSA-8gc5-j5rx-235r applies

Minor caution · medium confidence

A security scanner found a known vulnerability in one of the project's dependencies. However, this project builds its code into a single file before shipping, and many of its dependencies are only used during development, not included in what users actually install. Without knowing exactly which dependency is affected, it is unclear whether this vulnerability reaches end users at all.

Technical evidence

Scanner reason: OSV-Scanner matched advisory GHSA-8gc5-j5rx-235r to a dependency declared by this repository.

Contextual assessment: OSV-scanner matched a high-severity advisory in this package-lock.json. The lock file shows this is a build project that ships a bundled artifact (dist/index.js per the manifest). Many visible packages in the lock file are marked dev:true (Babel, esbuild, csstools, etc.) and are not included in the shipped extension. The scanner removed package details, so the specific affected package and whether it is a production or dev-only dependency cannot be confirmed. If the advisory affects a dev-only build tool, it has no runtime impact on end users. If it affects a production dependency bundled into the extension, runtime reachability depends on whether the vulnerable code path is included in the bundle and whether attacker-controlled input reaches it. Advisory severity alone does not establish immediate danger.

Impact: low · Exploitability: unlikely

Developer action: Update the affected dependency to a patched version when feasible, particularly if it is a production dependency. Run an audit with package details visible to identify which specific package is affected and whether it is shipped in the bundle.

Scanner
osv-scanner 2.4.0
Rule
GHSA-8gc5-j5rx-235r
File role
production
Source
package-lock.json

Dependency advisory GHSA-9cx6-37pm-9jff applies

Minor caution · medium confidence

A security scanner found a known vulnerability in one of the project's dependencies. Since this project bundles its code before shipping and many dependencies are only used during development, it is unclear whether this vulnerability affects what users actually install.

Technical evidence

Scanner reason: OSV-Scanner matched advisory GHSA-9cx6-37pm-9jff to a dependency declared by this repository.

Contextual assessment: OSV-scanner matched a high-severity advisory in this package-lock.json. The project ships as a Vite-built bundle (dist/index.js), and the lock file shows numerous dev-only dependencies that are not included in the shipped artifact. The scanner removed package details, preventing confirmation of whether the affected package is a production dependency bundled into the extension or a dev-only build tool. Without identifying the specific package, runtime reachability and attacker input paths cannot be assessed. Advisory severity alone is not an immediate-danger conclusion.

Impact: low · Exploitability: unlikely

Developer action: Update the affected dependency to a patched version when feasible. Run an audit with package details visible to identify the specific affected package and whether it ships in the bundle.

Scanner
osv-scanner 2.4.0
Rule
GHSA-9cx6-37pm-9jff
File role
production
Source
package-lock.json

Dependency advisory GHSA-37qj-frw5-hhjh applies

Minor caution · medium confidence

A security scanner found a known vulnerability in one of the project's dependencies. Because the project packages its code into a single file before distribution and many dependencies are development-only, it is uncertain whether this vulnerability reaches users.

Technical evidence

Scanner reason: OSV-Scanner matched advisory GHSA-37qj-frw5-hhjh to a dependency declared by this repository.

Contextual assessment: OSV-scanner matched a high-severity advisory in this package-lock.json. The extension manifest indicates the shipped artifact is a pre-built bundle (dist/index.js, dist/style.css), meaning dev dependencies in the lock file are not distributed to end users. The scanner removed package details, so the specific affected package cannot be identified. If the advisory targets a dev-only build tool, there is no end-user impact. If it targets a production dependency, the vulnerable code path may or may not be reachable in the bundled output. Without the package identity, a definitive reachability assessment is not possible.

Impact: low · Exploitability: unlikely

Developer action: Update the affected dependency to a patched version when feasible. Identify the specific affected package to determine whether it is shipped in the bundle.

Scanner
osv-scanner 2.4.0
Rule
GHSA-37qj-frw5-hhjh
File role
production
Source
package-lock.json

Dependency advisory GHSA-m7jm-9gc2-mpf2 applies

Minor caution · medium confidence

A security scanner found a critical vulnerability in one of the project's dependencies. However, this project bundles its code before shipping, and many dependencies are only used during development. Without knowing which specific dependency is affected, it is unclear whether this vulnerability actually reaches users.

Technical evidence

Scanner reason: OSV-Scanner matched advisory GHSA-m7jm-9gc2-mpf2 to a dependency declared by this repository.

Contextual assessment: OSV-scanner matched a critical-severity advisory in this package-lock.json. Despite the critical scanner rating, the project ships a Vite-built bundle rather than raw node_modules, and the lock file shows many dev-only dependencies that are excluded from the shipped artifact. The scanner removed package details, so the specific affected package cannot be confirmed. If this advisory targets a dev-only build tool such as Vite or esbuild, there is no runtime impact on end users. If it targets a production dependency, runtime reachability in the bundle and attacker-controlled input paths would need further analysis. Advisory severity alone does not establish immediate danger without confirming the affected package is shipped and its vulnerable code is reachable.

Impact: low · Exploitability: unlikely

Developer action: Prioritize updating the affected dependency to a patched version. Run an audit with package details visible to identify the specific affected package and confirm whether it is a production dependency included in the shipped bundle.

Scanner
osv-scanner 2.4.0
Rule
GHSA-m7jm-9gc2-mpf2
File role
production
Source
package-lock.json

Dependency advisory GHSA-4w7w-66w2-5vf9 applies

Minor caution · medium confidence

A security scanner found a medium-severity vulnerability in one of the project's dependencies. Since the project bundles its code before shipping and many dependencies are development-only, it is unclear whether this affects users.

Technical evidence

Scanner reason: OSV-Scanner matched advisory GHSA-4w7w-66w2-5vf9 to a dependency declared by this repository.

Contextual assessment: OSV-scanner matched a medium-severity advisory in this package-lock.json. The project distributes a pre-built bundle, and the lock file contains many dev-only dependencies not included in the shipped extension. The scanner removed package details, preventing identification of the specific affected package. Without knowing whether the advisory targets a production or dev-only dependency, runtime reachability cannot be determined. Medium-severity advisories in dev-only build tools have no end-user impact.

Impact: low · Exploitability: unlikely

Developer action: Update the affected dependency to a patched version when feasible. Identify the specific affected package to determine whether it ships in the bundle.

Scanner
osv-scanner 2.4.0
Rule
GHSA-4w7w-66w2-5vf9
File role
production
Source
package-lock.json

Dependency advisory GHSA-hmw2-7cc7-3qxx applies

Minor caution · medium confidence

A security scanner found a known vulnerability in one of the project's dependencies. Because the project bundles its code before shipping and many dependencies are development-only, it is uncertain whether this vulnerability reaches users.

Technical evidence

Scanner reason: OSV-Scanner matched advisory GHSA-hmw2-7cc7-3qxx to a dependency declared by this repository.

Contextual assessment: OSV-scanner matched a high-severity advisory in this package-lock.json. The extension ships as a Vite-built bundle, and the lock file shows numerous dev-only dependencies excluded from the shipped artifact. The scanner removed package details, so the specific affected package cannot be identified. If the advisory targets a dev-only build tool, there is no end-user impact. If it targets a production dependency bundled into the extension, runtime reachability depends on whether the vulnerable code path is included and reachable. Without the package identity, a definitive assessment is not possible.

Impact: low · Exploitability: unlikely

Developer action: Update the affected dependency to a patched version when feasible. Identify the specific affected package to determine whether it ships in the bundle.

Scanner
osv-scanner 2.4.0
Rule
GHSA-hmw2-7cc7-3qxx
File role
production
Source
package-lock.json

Dependency advisory GHSA-wf6x-7x77-mvgw applies

Minor caution · medium confidence

A security scanner found a known vulnerability in one of the project's dependencies. Since the project bundles its code before shipping and many dependencies are development-only, it is unclear whether this vulnerability affects users.

Technical evidence

Scanner reason: OSV-Scanner matched advisory GHSA-wf6x-7x77-mvgw to a dependency declared by this repository.

Contextual assessment: OSV-scanner matched a high-severity advisory in this package-lock.json. The project distributes a pre-built bundle per the manifest, and the lock file contains many dev-only dependencies not shipped to end users. The scanner removed package details, preventing identification of the specific affected package. Without knowing whether the advisory targets a production or dev-only dependency, runtime reachability in the shipped extension cannot be determined. Advisory severity alone does not establish immediate danger.

Impact: low · Exploitability: unlikely

Developer action: Update the affected dependency to a patched version when feasible. Identify the specific affected package to determine whether it ships in the bundle.

Scanner
osv-scanner 2.4.0
Rule
GHSA-wf6x-7x77-mvgw
File role
production
Source
package-lock.json

Dependency advisory GHSA-gh4j-gqv2-49f6 applies

Minor caution · medium confidence

A security scanner found a medium-severity vulnerability in one of the project's dependencies. Because the project bundles its code before shipping and many dependencies are development-only, it is uncertain whether this vulnerability reaches users.

Technical evidence

Scanner reason: OSV-Scanner matched advisory GHSA-gh4j-gqv2-49f6 to a dependency declared by this repository.

Contextual assessment: OSV-scanner matched a medium-severity advisory in this package-lock.json. The extension ships as a Vite-built bundle, and the lock file shows many dev-only dependencies excluded from the shipped artifact. The scanner removed package details, so the specific affected package cannot be identified. If the advisory targets a dev-only build tool, there is no end-user impact. If it targets a production dependency, runtime reachability depends on whether the vulnerable code path is included in the bundle. Without the package identity, a definitive assessment is not possible.

Impact: low · Exploitability: unlikely

Developer action: Update the affected dependency to a patched version when feasible. Identify the specific affected package to determine whether it ships in the bundle.

Scanner
osv-scanner 2.4.0
Rule
GHSA-gh4j-gqv2-49f6
File role
production
Source
package-lock.json

Dependency advisory GHSA-2w6w-674q-4c4q applies

Minor caution · medium confidence

The flagged critical issue is almost certainly in a build tool used only during development, not in the code that actually ships to users. End users installing this extension are not exposed to this vulnerability.

Technical evidence

Scanner reason: OSV-Scanner matched advisory GHSA-2w6w-674q-4c4q to a dependency declared by this repository.

Contextual assessment: This critical advisory most likely corresponds to a build-tool dependency such as vite, which is declared as a devDependency and is not bundled into the shipped extension output. The extension ships only dist/index.js and dist/style.css to end users. Build-tool vulnerabilities affecting the local development server do not create runtime attack surface for SillyTavern users who install the extension. Without the specific package name from the scanner, runtime reachability cannot be confirmed, but the project structure strongly indicates this is a development-only dependency.

Impact: none · Exploitability: unlikely

Developer action: Update the affected devDependency to the patched version as a best practice to protect the development environment.

Scanner
osv-scanner 2.4.0
Rule
GHSA-2w6w-674q-4c4q
File role
production
Source
package-lock.json

Dependency advisory GHSA-xjpj-3mr7-gcpf applies

Minor caution · medium confidence

The flagged issue is probably in a development tool that does not ship with the extension. Users who install the extension are not affected.

Technical evidence

Scanner reason: OSV-Scanner matched advisory GHSA-xjpj-3mr7-gcpf to a dependency declared by this repository.

Contextual assessment: This high-severity advisory likely affects a build-toolchain dependency in the vite, vitest, or related ecosystem, all of which are devDependencies. These packages are not included in the bundled dist/index.js that ships to SillyTavern users. The extension runs in the browser within SillyTavern's context and has no server-side component, so server-side build-tool vulnerabilities are not reachable at runtime.

Impact: none · Exploitability: unlikely

Developer action: Update the affected dependency to the patched version during the next build cycle.

Scanner
osv-scanner 2.4.0
Rule
GHSA-xjpj-3mr7-gcpf
File role
production
Source
package-lock.json

Dependency advisory GHSA-v56q-mh7h-f735 applies

Minor caution · medium confidence

The flagged issue is likely in a development-only tool that is not included in the extension users install.

Technical evidence

Scanner reason: OSV-Scanner matched advisory GHSA-v56q-mh7h-f735 to a dependency declared by this repository.

Contextual assessment: This high-severity advisory is most likely associated with a devDependency in the build toolchain. The shipped extension artifact is a browser bundle that excludes devDependencies. Without the specific package identification from the scanner, exact runtime reachability cannot be determined, but the project's dependency structure indicates the vulnerable code does not reach end users.

Impact: none · Exploitability: unlikely

Developer action: Update the affected dependency to the patched version.

Scanner
osv-scanner 2.4.0
Rule
GHSA-v56q-mh7h-f735
File role
production
Source
package-lock.json

Dependency advisory GHSA-6g55-p6wh-862q applies

Minor caution · medium confidence

The flagged issue is probably in a tool used only for building the extension, not in the code users receive.

Technical evidence

Scanner reason: OSV-Scanner matched advisory GHSA-6g55-p6wh-862q to a dependency declared by this repository.

Contextual assessment: This high-severity advisory likely targets a build-tool or transitive devDependency. The extension is a browser-based SillyTavern add-on that ships only the bundled output, not the full dependency tree. DevDependencies and their transitive dependencies are excluded from the shipped bundle, so the vulnerable code is not present in the end-user runtime.

Impact: none · Exploitability: unlikely

Developer action: Update the affected dependency to the patched version.

Scanner
osv-scanner 2.4.0
Rule
GHSA-6g55-p6wh-862q
File role
production
Source
package-lock.json

Dependency advisory GHSA-r28c-9q8g-f849 applies

Minor caution · medium confidence

The flagged issue is likely in a development tool that does not ship to users.

Technical evidence

Scanner reason: OSV-Scanner matched advisory GHSA-r28c-9q8g-f849 to a dependency declared by this repository.

Contextual assessment: This high-severity advisory is most likely for a build-toolchain dependency declared under devDependencies. The shipped extension bundle does not include devDependencies. The scanner removed specific package details, preventing definitive identification, but the project structure and the concentration of advisories in the vite and vitest ecosystem support the conclusion that this is a development-only dependency.

Impact: none · Exploitability: unlikely

Developer action: Update the affected dependency to the patched version.

Scanner
osv-scanner 2.4.0
Rule
GHSA-r28c-9q8g-f849
File role
production
Source
package-lock.json

Dependency advisory GHSA-xhpv-hc6g-r9c6 applies

Minor caution · low confidence

The flagged issue might be in a library that ships with the extension, but without knowing the exact package, we cannot confirm whether users are affected. The developer should check and update the dependency.

Technical evidence

Scanner reason: OSV-Scanner matched advisory GHSA-xhpv-hc6g-r9c6 to a dependency declared by this repository.

Contextual assessment: This high-severity advisory could potentially affect either a devDependency or a production dependency. If it affects a production dependency such as handlebars or fast-xml-parser, the extension does process LLM-generated content and character data through these libraries. However, the browser extension context limits the impact of many server-side vulnerability classes. Without the specific package name from the scanner, runtime reachability cannot be definitively assessed. The developer should verify which package is affected and whether the vulnerable code path is exercised in the shipped bundle.

Impact: low · Exploitability: unlikely

Developer action: Identify the affected package, update it to the patched version, and verify that the vulnerable code path is not reachable in the shipped bundle.

Scanner
osv-scanner 2.4.0
Rule
GHSA-xhpv-hc6g-r9c6
File role
production
Source
package-lock.json

Dependency advisory GHSA-xvcm-6775-5m9r applies

Minor caution · low confidence

The flagged issue may or may not affect the code users receive. The developer should identify the affected package and update it.

Technical evidence

Scanner reason: OSV-Scanner matched advisory GHSA-xvcm-6775-5m9r to a dependency declared by this repository.

Contextual assessment: This high-severity advisory could affect either a build-tool dependency or a production dependency. The scanner removed package details, preventing definitive identification. If the affected package is a devDependency, the vulnerable code does not ship to end users. If it is a production dependency, the browser extension context and the data flows within SillyTavern would need to be examined for runtime reachability. The advisory severity alone does not establish end-user harm.

Impact: low · Exploitability: unlikely

Developer action: Identify the affected package, update it to the patched version, and confirm the vulnerable code is not reachable in the shipped bundle.

Scanner
osv-scanner 2.4.0
Rule
GHSA-xvcm-6775-5m9r
File role
production
Source
package-lock.json

Dependency advisory GHSA-3v7f-55p6-f55p applies

Minor caution · medium confidence

The flagged issue is likely in a development tool or its sub-dependency that does not ship with the extension.

Technical evidence

Scanner reason: OSV-Scanner matched advisory GHSA-3v7f-55p6-f55p to a dependency declared by this repository.

Contextual assessment: This medium-severity advisory likely affects a transitive dependency in the build toolchain. Medium-severity advisories in this ecosystem commonly relate to development tools or their transitive dependencies, which are not included in the shipped browser extension bundle. The extension ships only the compiled dist output to end users.

Impact: none · Exploitability: unlikely

Developer action: Update the affected dependency to the patched version during the next maintenance cycle.

Scanner
osv-scanner 2.4.0
Rule
GHSA-3v7f-55p6-f55p
File role
production
Source
package-lock.json

Dependency advisory GHSA-3mfm-83xf-c92r applies

Minor caution · low confidence

A security scanner flagged a dependency in this project's build configuration. However, the specific package was not identified, and many dependencies in this file are only used during development, not in the final product users install. Without knowing which package is affected, it is unclear whether this poses any real risk to users.

Technical evidence

Scanner reason: OSV-Scanner matched advisory GHSA-3mfm-83xf-c92r to a dependency declared by this repository.

Contextual assessment: OSV-scanner matched advisory GHSA-3mfm-83xf-c92r against a dependency in the lockfile, but package details were removed so the specific affected package and version cannot be confirmed. The lockfile includes many dev-only build-tool dependencies (babel, esbuild, vite, vitest) that are not shipped in the compiled extension artifact (dist/index.js, dist/style.css). Without knowing which package matched, runtime reachability and attacker-controlled input paths cannot be determined. The advisory severity alone does not establish concrete user harm in this extension context.

Impact: low · Exploitability: unlikely

Developer action: Run an updated dependency audit with package details visible, identify the specific affected package, and update it if it is a production dependency or if the vulnerable code path is reachable.

Scanner
osv-scanner 2.4.0
Rule
GHSA-3mfm-83xf-c92r
File role
production
Source
package-lock.json

Dependency advisory GHSA-mw96-cpmx-2vgc applies

Minor caution · low confidence

A security scanner flagged a dependency in this project. The specific package was not identified, so it is unclear whether this affects the final product or only development tools. The risk to end users is uncertain but likely low.

Technical evidence

Scanner reason: OSV-Scanner matched advisory GHSA-mw96-cpmx-2vgc to a dependency declared by this repository.

Contextual assessment: OSV-scanner matched advisory GHSA-mw96-cpmx-2vgc against a dependency in the lockfile, but package details were removed. The lockfile contains both production dependencies (diff, fast-xml-parser, handlebars, react, react-dom, sillytavern-utils-lib, zod) and numerous dev-only dependencies. The shipped extension is a compiled bundle, so dev dependencies do not reach end users. Without the specific package identity, version, and whether the vulnerable code is bundled into the production output, concrete user harm cannot be established.

Impact: low · Exploitability: unlikely

Developer action: Run an updated dependency audit with package details visible, identify the specific affected package, and update it if it is a production dependency or if the vulnerable code path is reachable.

Scanner
osv-scanner 2.4.0
Rule
GHSA-mw96-cpmx-2vgc
File role
production
Source
package-lock.json

Dependency advisory GHSA-v2wj-q39q-566r applies

Minor caution · low confidence

A security scanner flagged a dependency in this project. The specific package was not identified, so it is unclear whether this affects the final product or only development tools. The risk to end users is uncertain but likely low.

Technical evidence

Scanner reason: OSV-Scanner matched advisory GHSA-v2wj-q39q-566r to a dependency declared by this repository.

Contextual assessment: OSV-scanner matched advisory GHSA-v2wj-q39q-566r against a dependency in the lockfile, but package details were removed. The extension ships as compiled dist artifacts, and the lockfile includes many dev-only toolchain dependencies that do not ship to end users. Without the specific package and version, runtime reachability of the vulnerable code in the production bundle cannot be determined.

Impact: low · Exploitability: unlikely

Developer action: Run an updated dependency audit with package details visible, identify the specific affected package, and update it if it is a production dependency or if the vulnerable code path is reachable.

Scanner
osv-scanner 2.4.0
Rule
GHSA-v2wj-q39q-566r
File role
production
Source
package-lock.json

Dependency advisory GHSA-fj3w-jwp8-x2g3 applies

Minor caution · low confidence

A security scanner flagged a low-severity issue in a dependency. The specific package was not identified, and the severity is low. The risk to end users is likely minimal.

Technical evidence

Scanner reason: OSV-Scanner matched advisory GHSA-fj3w-jwp8-x2g3 to a dependency declared by this repository.

Contextual assessment: OSV-scanner matched low-severity advisory GHSA-fj3w-jwp8-x2g3 against a dependency in the lockfile, but package details were removed. The low scanner severity and the absence of package identity mean concrete user harm cannot be established. The extension ships compiled artifacts, and many lockfile entries are dev-only dependencies.

Impact: low · Exploitability: unlikely

Developer action: Run an updated dependency audit with package details visible and update the affected package if feasible.

Scanner
osv-scanner 2.4.0
Rule
GHSA-fj3w-jwp8-x2g3
File role
production
Source
package-lock.json

Dependency advisory GHSA-qx2v-qp2m-jg93 applies

Minor caution · low confidence

A security scanner flagged a medium-severity issue in a dependency. The specific package was not identified, so it is unclear whether this affects the final product. The risk to end users is uncertain but likely low.

Technical evidence

Scanner reason: OSV-Scanner matched advisory GHSA-qx2v-qp2m-jg93 to a dependency declared by this repository.

Contextual assessment: OSV-scanner matched medium-severity advisory GHSA-qx2v-qp2m-jg93 against a dependency in the lockfile, but package details were removed. Without the specific package and version, it is impossible to determine whether the vulnerable code is a production dependency bundled into the shipped extension or a dev-only dependency. Runtime reachability and attacker input paths cannot be assessed.

Impact: low · Exploitability: unlikely

Developer action: Run an updated dependency audit with package details visible, identify the specific affected package, and update it if it is a production dependency or if the vulnerable code path is reachable.

Scanner
osv-scanner 2.4.0
Rule
GHSA-qx2v-qp2m-jg93
File role
production
Source
package-lock.json

Dependency advisory GHSA-fxqj-rqcc-2cmp applies

Minor caution · low confidence

A security scanner flagged a medium-severity issue in a dependency. The specific package was not identified, so it is unclear whether this affects the final product. The risk to end users is uncertain but likely low.

Technical evidence

Scanner reason: OSV-Scanner matched advisory GHSA-fxqj-rqcc-2cmp to a dependency declared by this repository.

Contextual assessment: OSV-scanner matched medium-severity advisory GHSA-fxqj-rqcc-2cmp against a dependency in the lockfile, but package details were removed. Without the specific package identity and version, runtime reachability in the production bundle cannot be determined. The extension ships compiled artifacts, and many lockfile entries are dev-only dependencies that do not reach end users.

Impact: low · Exploitability: unlikely

Developer action: Run an updated dependency audit with package details visible, identify the specific affected package, and update it if it is a production dependency or if the vulnerable code path is reachable.

Scanner
osv-scanner 2.4.0
Rule
GHSA-fxqj-rqcc-2cmp
File role
production
Source
package-lock.json

Dependency advisory GHSA-96hv-2xvq-fx4p applies

Minor caution · low confidence

A security scanner flagged a high-severity issue in a dependency. However, the specific package was not identified, and many dependencies in this file are only used during development. Without knowing which package is affected, the real risk to users is uncertain.

Technical evidence

Scanner reason: OSV-Scanner matched advisory GHSA-96hv-2xvq-fx4p to a dependency declared by this repository.

Contextual assessment: OSV-scanner matched high-severity advisory GHSA-96hv-2xvq-fx4p against a dependency in the lockfile, but package details were removed. Despite the high scanner severity, without the specific package and version, it cannot be determined whether the vulnerable code is bundled into the shipped extension or is a dev-only dependency. Advisory severity alone does not establish concrete user harm in this extension context.

Impact: low · Exploitability: unlikely

Developer action: Run an updated dependency audit with package details visible, identify the specific affected package, and update it if it is a production dependency or if the vulnerable code path is reachable.

Scanner
osv-scanner 2.4.0
Rule
GHSA-96hv-2xvq-fx4p
File role
production
Source
package-lock.json

Dependency advisory GHSA-442j-39wm-28r2 applies

Minor caution · low confidence

A security scanner flagged a low-severity issue in a dependency. The specific package was not identified, and the severity is low. The risk to end users is likely minimal.

Technical evidence

Scanner reason: OSV-Scanner matched advisory GHSA-442j-39wm-28r2 to a dependency declared by this repository.

Contextual assessment: OSV-scanner matched low-severity advisory GHSA-442j-39wm-28r2 against a dependency in the lockfile, but package details were removed. The low scanner severity and the absence of package identity mean concrete user harm cannot be established. The extension ships compiled artifacts, and many lockfile entries are dev-only dependencies.

Impact: low · Exploitability: unlikely

Developer action: Run an updated dependency audit with package details visible and update the affected package if feasible.

Scanner
osv-scanner 2.4.0
Rule
GHSA-442j-39wm-28r2
File role
production
Source
package-lock.json

Dependency advisory GHSA-58qx-3vcg-4xpx applies

Minor caution · medium confidence

A security scanner found a known issue in a package used by this project. The package is most likely a development tool that is not included in the actual extension users install, so it should not affect people using the extension.

Technical evidence

Scanner reason: OSV-Scanner matched advisory GHSA-58qx-3vcg-4xpx to a dependency declared by this repository.

Contextual assessment: OSV-scanner matched a medium-severity advisory against a dependency declared in the lockfile. The project ships a Vite-bundled dist/index.js and dist/style.css as its SillyTavern extension artifact; build-time and test-time devDependencies are not included in the shipped output. The advisory most likely corresponds to a build-tool or transitive dev dependency that has no runtime reachability in the installed extension. Even if it touched a production dependency, the extension executes in a browser context within SillyTavern with limited attacker-controlled input paths to the vulnerable code. No concrete end-user harm is demonstrated by the available evidence.

Impact: low · Exploitability: unlikely

Developer action: Update the flagged dependency to a patched version when convenient to keep the development environment current.

Scanner
osv-scanner 2.4.0
Rule
GHSA-58qx-3vcg-4xpx
File role
production
Source
package-lock.json

Dependency advisory GHSA-c2c7-rcm5-vvqj applies

Minor caution · medium confidence

A scanner flagged a serious-sounding issue in a package, but the package is most likely a build tool that stays on the developer's machine and is not part of what users install. The risk to extension users is low.

Technical evidence

Scanner reason: OSV-Scanner matched advisory GHSA-c2c7-rcm5-vvqj to a dependency declared by this repository.

Contextual assessment: OSV-scanner matched a high-severity advisory against a dependency in the lockfile. The project manifest shows the extension artifact is a Vite production build (dist/index.js); devDependencies such as Vite, Vitest, jsdom, and their transitive dependencies are not shipped to end users. High-severity advisories in build tooling commonly affect the local dev server or build pipeline rather than the bundled output. Without the full lockfile showing the exact flagged package and version, the most probable target is a build-tool dependency with no runtime reachability in the installed extension. No attacker-controlled input path to the vulnerable code in a deployed context is evident.

Impact: low · Exploitability: unlikely

Developer action: Update the flagged dependency to a patched version to maintain a secure development environment.

Scanner
osv-scanner 2.4.0
Rule
GHSA-c2c7-rcm5-vvqj
File role
production
Source
package-lock.json

Dependency advisory GHSA-2qvq-rjwj-gvw9 applies

Minor caution · medium confidence

A scanner found a moderate issue in a package used during development. Since the package is likely not included in the final extension, it should not impact users who install it.

Technical evidence

Scanner reason: OSV-Scanner matched advisory GHSA-2qvq-rjwj-gvw9 to a dependency declared by this repository.

Contextual assessment: OSV-scanner matched a medium-severity advisory against a dependency in the lockfile. The shipped extension consists of a Vite-bundled JavaScript file and CSS; development and test dependencies are excluded from the artifact. The advisory likely targets a transitive dev dependency or build tool with no code path reachable at runtime in the installed extension. The browser-based execution context within SillyTavern further limits the attack surface for most dependency-class vulnerabilities. No concrete user harm is demonstrated.

Impact: low · Exploitability: unlikely

Developer action: Update the flagged dependency to a patched version when convenient.

Scanner
osv-scanner 2.4.0
Rule
GHSA-2qvq-rjwj-gvw9
File role
production
Source
package-lock.json

Dependency advisory GHSA-fx2h-pf6j-xcff applies

Minor caution · medium confidence

A scanner flagged a serious issue in a package, but it is most likely a development tool that does not ship with the extension. The risk to people using the extension is low.

Technical evidence

Scanner reason: OSV-Scanner matched advisory GHSA-fx2h-pf6j-xcff to a dependency declared by this repository.

Contextual assessment: OSV-scanner matched a high-severity advisory against a dependency in the lockfile. The project structure indicates the extension is distributed as a Vite production build, meaning devDependencies and their transitive packages are not present in the installed extension. High-severity advisories commonly associated with build tooling affect the development server or build pipeline, not the bundled output served to SillyTavern users. The available evidence does not show attacker-controlled input reaching vulnerable code in a deployed context. No concrete end-user harm is demonstrated.

Impact: low · Exploitability: unlikely

Developer action: Update the flagged dependency to a patched version to keep the build toolchain secure.

Scanner
osv-scanner 2.4.0
Rule
GHSA-fx2h-pf6j-xcff
File role
production
Source
package-lock.json
Expected scanner matches (0)

None.

Related contextual observations

All advisories are in a build-project lock file with bundled output and many dev-only dependencies

low risk · medium confidence

All eight vulnerability findings come from the project's dependency list, but the project bundles its code into a single file before shipping. Many of its dependencies are only used during development and are not included in what users install. The scanner did not include the names of the affected packages, so it is unclear whether any of these vulnerabilities actually reach end users. Running a dependency audit that shows package names would help clarify the real impact.

Technical assessment

The file is for a Vite-based build project whose manifest declares dist/index.js and dist/style.css as the shipped artifacts. The visible portion of the lock file shows that Babel, esbuild, csstools, and other packages are marked dev:true, meaning they are not included in the shipped extension. The scanner removed package details for all eight advisories, so it is not possible to confirm which specific packages are affected, whether they are production or dev-only dependencies, or whether their vulnerable code paths are reachable in the bundled output. The production dependencies (diff, fast-xml-parser, handlebars, react, react-dom, sillytavern-utils-lib, zod) are bundled by Vite into the shipped extension, but whether any of the eight advisories target these packages cannot be determined from the supplied evidence. Running npm audit or osv-scanner with package details visible would clarify which packages are affected and whether they ship in the bundle.

Impact: low · Exploitability: unlikely

Developer action: Run npm audit or osv-scanner with full package details visible to identify each affected package. For production dependencies that are bundled into the shipped extension, update to patched versions. For dev-only dependencies, update when convenient but note they do not affect end users.

Sources:

Scanner removed package details preventing definitive runtime reachability analysis

low risk · low confidence

The security scanner did not include the names of the affected packages, making it hard to know for certain whether any of these issues affect the code that users actually install. The developer should run a more detailed scan to identify the specific packages and update them.

Technical assessment

The OSV-scanner candidates do not include the affected package name or version, which prevents definitive determination of whether each advisory impacts a devDependency or a production dependency. The project declares production dependencies including handlebars, fast-xml-parser, zod, diff, and sillytavern-utils-lib, any of which could be the subject of an advisory. The developer should run a dependency audit with package names visible to confirm which advisories affect production code and verify that vulnerable code paths are not exercised in the shipped bundle.

Impact: low · Exploitability: unlikely

Developer action: Run a dependency vulnerability scan that includes package names and versions, then update all affected production dependencies to patched versions.

Sources:

All advisory matches lack package identity, preventing runtime reachability assessment

low risk · low confidence

The security scanner flagged eight dependency issues but did not include which specific packages were affected. This project uses many tools that only run during development and are not included in the final product. Without knowing which packages match which warnings, it is impossible to say whether any of these issues actually affect users of the extension.

Technical assessment

Every OSV-scanner candidate in this lockfile had its package details removed by the scanner. The lockfile contains a mix of production dependencies (diff, fast-xml-parser, handlebars, react, react-dom, sillytavern-utils-lib, zod) and numerous dev-only build-tool dependencies (babel, esbuild, vite, vitest, sass, jsdom, prettier, typescript). The extension ships as compiled dist/index.js and dist/style.css per the manifest, meaning dev-only dependencies do not reach end users. Without knowing which specific package and version each advisory matched, it is impossible to determine whether the vulnerable code is bundled into the production output, whether attacker-controlled input reaches the vulnerable code path, or what concrete user harm could result. All eight candidates are therefore assessed as minor weaknesses with low confidence.

Impact: low · Exploitability: unlikely

Developer action: Re-run the dependency scan with full package details visible so each advisory can be mapped to a specific package and version. Then update any affected production dependencies, or confirm that affected packages are dev-only and not bundled into the shipped extension.

Sources:

Dependency advisories likely affect build tooling rather than shipped extension

low risk · medium confidence

The security warnings are most likely about tools used to build the extension, not the extension itself. Users who install the extension are probably not affected. The developer should still update these packages to keep their build environment healthy.

Technical assessment

All four OSV-scanner candidates target dependencies in a project whose manifest declares the shipped artifact as a Vite production build (dist/index.js and dist/style.css). The direct devDependencies include Vite, Vitest, jsdom, sass, and related packages whose advisories commonly concern the local development server or build pipeline. These packages are not bundled into the extension output and therefore have no runtime reachability for end users. The production dependencies (diff, fast-xml-parser, handlebars, react, react-dom, sillytavern-utils-lib, zod) are bundled by Vite, but the available evidence does not identify any of them as the flagged package, nor does it show attacker-controlled input reaching a vulnerable code path. Running a fresh npm audit or osv-scanner with package details visible would confirm which specific packages and versions are flagged and whether any are production dependencies.

Impact: low · Exploitability: unlikely

Developer action: Run the scanner with package names visible to confirm whether any flagged dependency is a production dependency bundled into the extension output. Update all flagged packages to patched versions.

Sources:

Coverage and limitations

Tools

Limitations

Technical scan identity