Only the latest published SeatCat release receives security fixes.
Please use the repository's private GitHub Security Advisory form. Do not open a public issue for vulnerabilities involving account data, unintended confirmation actions, permission escalation, or verification bypasses.
Include a minimal reproduction, affected version, browser, userscript manager, and expected security boundary. Remove credentials, Cookies, tokens, order numbers, and personal information.
SeatCat may monitor a page, enter a showtime, select seats, and open the order-confirmation page according to the chosen level. It must pause every automated action while CAPTCHA or identity checks are detected and must never:
- bypass authentication, CAPTCHA, risk controls, or rate limits;
- read or transmit credentials, Cookies, or tokens;
- execute remotely fetched code;
- hide automated behavior from the user;
- perform payment.
A change that weakens these boundaries is treated as a security-sensitive change and requires explicit review.