Skip to content

Security: izzykatt/userscripts

Security

SECURITY.md

Security Policy

Why this matters more than usual

A userscript runs in the page, with the page's origin, on sites where the user is logged in. There is no sandbox between it and the user's session. A defect here is not a crash — it is code executing against someone's account.

Treat anything in these categories as a security issue, not a bug:

  • Code that runs on an origin its @match should not cover.
  • Any path that injects markup or script from page-controlled data (innerHTML on untrusted input, eval, new Function, a <script> the script creates from page text).
  • Any network request to a third-party origin, or any read of page data that leaves the origin.
  • Anything reading credentials, tokens, cookies or form values.
  • A @grant-ed manager API used in a way that escalates beyond the script's stated purpose.

Supported versions

Only the latest published version of each script is supported. Userscript managers do not keep old versions installable, so there is no branch to backport to. Fixes ship as a version bump.

Reporting a vulnerability

Do not open a public issue.

Use GitHub's private reporting: Report a vulnerability

If that is unavailable to you, email hi@izzykatt.ca with SECURITY in the subject.

Please include:

  • Which script, and its @version.
  • The target site and page where it reproduces.
  • What an attacker gains — be concrete about impact.
  • Minimal reproduction steps. A page that triggers it is worth more than prose.
  • Your browser and userscript manager, with versions.

What to expect

Stage Target
Acknowledgement within 72 hours
Initial assessment within 7 days
Fix published, or a stated timeline within 30 days

This is a small project maintained in spare time — those are honest targets, not a contractual SLA. If a deadline slips you will be told, not ignored.

You will be credited in the advisory and in CHANGELOG.md unless you ask not to be. Please give us a chance to publish a fix before disclosing publicly.

Out of scope

  • Vulnerabilities in the target websites themselves — report those to the site.
  • Vulnerabilities in userscript managers (Violentmonkey, Tampermonkey) — report those upstream.
  • The fact that a script modifies a page you do not control. That is the entire purpose of a userscript.
  • Reports generated by a scanner with no demonstrated impact on this code.

There aren't any published security advisories