A userscript runs in the page, with the page's origin, on sites where the user is logged in. There is no sandbox between it and the user's session. A defect here is not a crash — it is code executing against someone's account.
Treat anything in these categories as a security issue, not a bug:
- Code that runs on an origin its
@matchshould not cover. - Any path that injects markup or script from page-controlled data
(
innerHTMLon untrusted input,eval,new Function, a<script>the script creates from page text). - Any network request to a third-party origin, or any read of page data that leaves the origin.
- Anything reading credentials, tokens, cookies or form values.
- A
@grant-ed manager API used in a way that escalates beyond the script's stated purpose.
Only the latest published version of each script is supported. Userscript managers do not keep old versions installable, so there is no branch to backport to. Fixes ship as a version bump.
Do not open a public issue.
Use GitHub's private reporting: Report a vulnerability
If that is unavailable to you, email hi@izzykatt.ca with SECURITY in the
subject.
Please include:
- Which script, and its
@version. - The target site and page where it reproduces.
- What an attacker gains — be concrete about impact.
- Minimal reproduction steps. A page that triggers it is worth more than prose.
- Your browser and userscript manager, with versions.
| Stage | Target |
|---|---|
| Acknowledgement | within 72 hours |
| Initial assessment | within 7 days |
| Fix published, or a stated timeline | within 30 days |
This is a small project maintained in spare time — those are honest targets, not a contractual SLA. If a deadline slips you will be told, not ignored.
You will be credited in the advisory and in CHANGELOG.md unless you ask not to
be. Please give us a chance to publish a fix before disclosing publicly.
- Vulnerabilities in the target websites themselves — report those to the site.
- Vulnerabilities in userscript managers (Violentmonkey, Tampermonkey) — report those upstream.
- The fact that a script modifies a page you do not control. That is the entire purpose of a userscript.
- Reports generated by a scanner with no demonstrated impact on this code.