Security: jeph/venmo-cli

.github/SECURITY.md

Security Policy

Supported versions

venmo-cli is currently alpha software built on reverse-engineered, non-public Venmo endpoints. Only the latest published release receives security fixes.

VersionSecurity updates
Latest releaseSupported
Older releasesNot supported
Unreleased commitsNot supported

Before reporting a problem, reproduce it with the latest release when it is safe to do so.

Reporting a vulnerability

Do not disclose suspected vulnerabilities in a public issue, discussion, pull request, or social media post. Submit a private vulnerability report instead.

Include enough information to investigate without exposing private data:

  • The affected venmo-cli version, operating system, and CPU architecture.
  • The security impact and who could exploit it.
  • Minimal reproduction steps or a proof of concept.
  • Sanitized command output or debug diagnostics, if relevant.
  • Any suggested mitigation or fix.

Never include bearer tokens, v_id cookies, OTP codes, keyring contents, bank or card details, transaction identifiers, usernames, payment notes, amounts, or other personal or financial data. The maintainer will not ask you to provide authentication secrets.

Reports will be assessed privately. If the report is accepted, the maintainer will coordinate a fix, a release, and public disclosure as appropriate. Please allow time to investigate before publishing details. Reporters can be credited in a published advisory if they want attribution.

In scope

Examples of security issues in venmo-cli include:

  • Exposure or insecure storage of Venmo credentials or device identifiers.
  • Sensitive data appearing in normal output, JSON output, errors, or debug logs.
  • A way to bypass confirmation, --dry-run, funding-source selection, visibility, or other mutation safety controls.
  • Incorrect outcome handling that could make a financial mutation unsafe to retry.
  • Authentication or OTP handling that weakens account security.
  • Release artifact, signing, update, or packaging issues that could allow code substitution.
  • Local privilege or file-permission flaws caused by venmo-cli.

Out of scope

The following are not vulnerabilities in this project by themselves:

  • A non-public Venmo endpoint changing, disappearing, or rejecting a request.
  • Venmo service availability, rate limits, account policy, fees, or eligibility decisions.
  • Social engineering or phishing that does not exploit venmo-cli.
  • Vulnerabilities that require a user to intentionally provide an attacker with credentials or unrestricted access to an already unlocked account.

Vulnerabilities in Venmo or PayPal systems are outside this project's control and should be reported through their official security process. You may also notify this project privately when a CLI-side mitigation could protect venmo-cli users.

Safe research

  • Test only with accounts and data you own or have explicit permission to use.
  • Prefer --dry-run and non-mutating commands. Do not complete a real payment or transfer solely to demonstrate a vulnerability.
  • Do not access, retain, or disclose another person's data.
  • Do not disrupt Venmo, PayPal, this repository, or other users.
  • Stop testing if you encounter data or access outside your authorization.

There aren't any published security advisories

, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Add copy buttons to all
 blocks\n(function() {\n function addCopyButtons() {\n document.querySelectorAll('pre code').forEach(function(codeBlock) {\n if (codeBlock.parentElement.hasAttribute('data-copy-added')) return;\n codeBlock.parentElement.setAttribute('data-copy-added', 'true');\n \n var btn = document.createElement('button');\n btn.textContent = 'Copy';\n btn.style.cssText = 'position:absolute;top:4px;right:4px;padding:2px 8px;font-size:11px;background:#4ecdc4;border:none;border-radius:4px;color:#1a1a2e;cursor:pointer;opacity:0.7;transition:opacity 0.2s;';\n btn.onmouseover = function() { this.style.opacity = '1'; };\n btn.onmouseout = function() { this.style.opacity = '0.7'; };\n btn.onclick = function() {\n navigator.clipboard.writeText(codeBlock.textContent).then(function() {\n btn.textContent = 'Copied!';\n setTimeout(function() { btn.textContent = 'Copy'; }, 1500);\n });\n };\n codeBlock.parentElement.style.position = 'relative';\n codeBlock.parentElement.appendChild(btn);\n });\n }\n \n addCopyButtons();\n \n // Re-run on dynamic content\n var observer = new MutationObserver(addCopyButtons);\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "Add Copy Buttons to Code Blocks");
}
} catch(__e) { console.warn('[Userscript:Add Copy Buttons to Code Blocks]', __e); }
})();
(function(){
try {
var __m = "github.com";
var __re = new RegExp('^' + "github\\.com" + '
Skip to content

Security: jeph/venmo-cli

.github/SECURITY.md

Security Policy

Supported versions

venmo-cli is currently alpha software built on reverse-engineered, non-public Venmo endpoints. Only the latest published release receives security fixes.

VersionSecurity updates
Latest releaseSupported
Older releasesNot supported
Unreleased commitsNot supported

Before reporting a problem, reproduce it with the latest release when it is safe to do so.

Reporting a vulnerability

Do not disclose suspected vulnerabilities in a public issue, discussion, pull request, or social media post. Submit a private vulnerability report instead.

Include enough information to investigate without exposing private data:

  • The affected venmo-cli version, operating system, and CPU architecture.
  • The security impact and who could exploit it.
  • Minimal reproduction steps or a proof of concept.
  • Sanitized command output or debug diagnostics, if relevant.
  • Any suggested mitigation or fix.

Never include bearer tokens, v_id cookies, OTP codes, keyring contents, bank or card details, transaction identifiers, usernames, payment notes, amounts, or other personal or financial data. The maintainer will not ask you to provide authentication secrets.

Reports will be assessed privately. If the report is accepted, the maintainer will coordinate a fix, a release, and public disclosure as appropriate. Please allow time to investigate before publishing details. Reporters can be credited in a published advisory if they want attribution.

In scope

Examples of security issues in venmo-cli include:

  • Exposure or insecure storage of Venmo credentials or device identifiers.
  • Sensitive data appearing in normal output, JSON output, errors, or debug logs.
  • A way to bypass confirmation, --dry-run, funding-source selection, visibility, or other mutation safety controls.
  • Incorrect outcome handling that could make a financial mutation unsafe to retry.
  • Authentication or OTP handling that weakens account security.
  • Release artifact, signing, update, or packaging issues that could allow code substitution.
  • Local privilege or file-permission flaws caused by venmo-cli.

Out of scope

The following are not vulnerabilities in this project by themselves:

  • A non-public Venmo endpoint changing, disappearing, or rejecting a request.
  • Venmo service availability, rate limits, account policy, fees, or eligibility decisions.
  • Social engineering or phishing that does not exploit venmo-cli.
  • Vulnerabilities that require a user to intentionally provide an attacker with credentials or unrestricted access to an already unlocked account.

Vulnerabilities in Venmo or PayPal systems are outside this project's control and should be reported through their official security process. You may also notify this project privately when a CLI-side mitigation could protect venmo-cli users.

Safe research

  • Test only with accounts and data you own or have explicit permission to use.
  • Prefer --dry-run and non-mutating commands. Do not complete a real payment or transfer solely to demonstrate a vulnerability.
  • Do not access, retain, or disclose another person's data.
  • Do not disrupt Venmo, PayPal, this repository, or other users.
  • Stop testing if you encounter data or access outside your authorization.

There aren't any published security advisories

, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Force GitHub README to respect dark mode\n(function() {\n var style = document.createElement('style');\n style.textContent = '\n .markdown-body {\n color-scheme: dark light;\n }\n .markdown-body pre { background: #161b22 !important; }\n .markdown-body code { background: rgba(110, 118, 129, 0.4) !important; }\n .markdown-body table th, .markdown-body table td { border-color: #30363d !important; }\n .markdown-body img { background: #0d1117; }\n .markdown-body blockquote { border-left-color: #8b949e; }\n .markdown-body hr { border-color: #30363d; }\n ';\n document.head.appendChild(style);\n})();", "GitHub Dark Mode README Fix"); } } catch(__e) { console.warn('[Userscript:GitHub Dark Mode README Fix]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

Security: jeph/venmo-cli

.github/SECURITY.md

Security Policy

Supported versions

venmo-cli is currently alpha software built on reverse-engineered, non-public Venmo endpoints. Only the latest published release receives security fixes.

VersionSecurity updates
Latest releaseSupported
Older releasesNot supported
Unreleased commitsNot supported

Before reporting a problem, reproduce it with the latest release when it is safe to do so.

Reporting a vulnerability

Do not disclose suspected vulnerabilities in a public issue, discussion, pull request, or social media post. Submit a private vulnerability report instead.

Include enough information to investigate without exposing private data:

  • The affected venmo-cli version, operating system, and CPU architecture.
  • The security impact and who could exploit it.
  • Minimal reproduction steps or a proof of concept.
  • Sanitized command output or debug diagnostics, if relevant.
  • Any suggested mitigation or fix.

Never include bearer tokens, v_id cookies, OTP codes, keyring contents, bank or card details, transaction identifiers, usernames, payment notes, amounts, or other personal or financial data. The maintainer will not ask you to provide authentication secrets.

Reports will be assessed privately. If the report is accepted, the maintainer will coordinate a fix, a release, and public disclosure as appropriate. Please allow time to investigate before publishing details. Reporters can be credited in a published advisory if they want attribution.

In scope

Examples of security issues in venmo-cli include:

  • Exposure or insecure storage of Venmo credentials or device identifiers.
  • Sensitive data appearing in normal output, JSON output, errors, or debug logs.
  • A way to bypass confirmation, --dry-run, funding-source selection, visibility, or other mutation safety controls.
  • Incorrect outcome handling that could make a financial mutation unsafe to retry.
  • Authentication or OTP handling that weakens account security.
  • Release artifact, signing, update, or packaging issues that could allow code substitution.
  • Local privilege or file-permission flaws caused by venmo-cli.

Out of scope

The following are not vulnerabilities in this project by themselves:

  • A non-public Venmo endpoint changing, disappearing, or rejecting a request.
  • Venmo service availability, rate limits, account policy, fees, or eligibility decisions.
  • Social engineering or phishing that does not exploit venmo-cli.
  • Vulnerabilities that require a user to intentionally provide an attacker with credentials or unrestricted access to an already unlocked account.

Vulnerabilities in Venmo or PayPal systems are outside this project's control and should be reported through their official security process. You may also notify this project privately when a CLI-side mitigation could protect venmo-cli users.

Safe research

  • Test only with accounts and data you own or have explicit permission to use.
  • Prefer --dry-run and non-mutating commands. Do not complete a real payment or transfer solely to demonstrate a vulnerability.
  • Do not access, retain, or disclose another person's data.
  • Do not disrupt Venmo, PayPal, this repository, or other users.
  • Stop testing if you encounter data or access outside your authorization.

There aren't any published security advisories

, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Highlight search terms from Google/DuckDuckGo/Bing referrer\n(function() {\n var ref = document.referrer;\n var terms = [];\n \n if (ref.includes('google.com') || ref.includes('duckduckgo.com') || ref.includes('bing.com')) {\n var url = new URL(ref);\n var q = url.searchParams.get('q') || url.searchParams.get('p');\n if (q) {\n terms = q.split(/\\s+/).filter(function(t) { return t.length > 2; });\n }\n }\n \n if (terms.length === 0) return;\n \n var style = document.createElement('style');\n style.textContent = '.userscript-highlight { background: #fbbf24; color: #1a1a2e; padding: 1px 3px; border-radius: 2px; }';\n document.head.appendChild(style);\n \n function highlight(node) {\n if (node.nodeType === 3) { // text node\n var text = node.textContent;\n var found = false;\n terms.forEach(function(term) {\n var regex = new RegExp('(' + term.replace(/[.*+?^${}()|[\\]\\\\]/g, '\\\\') + ')', 'gi');\n if (regex.test(text)) {\n found = true;\n var frag = document.createDocumentFragment();\n var parts = text.split(regex);\n parts.forEach(function(part, i) {\n if (i % 2 === 0) {\n frag.appendChild(document.createTextNode(part));\n } else {\n var span = document.createElement('span');\n span.className = 'userscript-highlight';\n span.textContent = part;\n frag.appendChild(span);\n }\n });\n node.parentNode.replaceChild(frag, node);\n }\n });\n } else if (node.nodeType === 1 && node.childNodes) { // element\n var skipTags = ['SCRIPT', 'STYLE', 'NOSCRIPT', 'TEXTAREA', 'INPUT', 'SELECT'];\n if (!skipTags.includes(node.tagName)) {\n Array.from(node.childNodes).forEach(highlight);\n }\n }\n }\n \n highlight(document.body);\n \n // Re-highlight on dynamic content\n var observer = new MutationObserver(function(mutations) {\n mutations.forEach(function(m) {\n m.addedNodes.forEach(function(node) {\n if (node.nodeType === 1 || node.nodeType === 3) highlight(node);\n });\n });\n });\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "Highlight Search Terms"); } } catch(__e) { console.warn('[Userscript:Highlight Search Terms]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

Security: jeph/venmo-cli

.github/SECURITY.md

Security Policy

Supported versions

venmo-cli is currently alpha software built on reverse-engineered, non-public Venmo endpoints. Only the latest published release receives security fixes.

VersionSecurity updates
Latest releaseSupported
Older releasesNot supported
Unreleased commitsNot supported

Before reporting a problem, reproduce it with the latest release when it is safe to do so.

Reporting a vulnerability

Do not disclose suspected vulnerabilities in a public issue, discussion, pull request, or social media post. Submit a private vulnerability report instead.

Include enough information to investigate without exposing private data:

  • The affected venmo-cli version, operating system, and CPU architecture.
  • The security impact and who could exploit it.
  • Minimal reproduction steps or a proof of concept.
  • Sanitized command output or debug diagnostics, if relevant.
  • Any suggested mitigation or fix.

Never include bearer tokens, v_id cookies, OTP codes, keyring contents, bank or card details, transaction identifiers, usernames, payment notes, amounts, or other personal or financial data. The maintainer will not ask you to provide authentication secrets.

Reports will be assessed privately. If the report is accepted, the maintainer will coordinate a fix, a release, and public disclosure as appropriate. Please allow time to investigate before publishing details. Reporters can be credited in a published advisory if they want attribution.

In scope

Examples of security issues in venmo-cli include:

  • Exposure or insecure storage of Venmo credentials or device identifiers.
  • Sensitive data appearing in normal output, JSON output, errors, or debug logs.
  • A way to bypass confirmation, --dry-run, funding-source selection, visibility, or other mutation safety controls.
  • Incorrect outcome handling that could make a financial mutation unsafe to retry.
  • Authentication or OTP handling that weakens account security.
  • Release artifact, signing, update, or packaging issues that could allow code substitution.
  • Local privilege or file-permission flaws caused by venmo-cli.

Out of scope

The following are not vulnerabilities in this project by themselves:

  • A non-public Venmo endpoint changing, disappearing, or rejecting a request.
  • Venmo service availability, rate limits, account policy, fees, or eligibility decisions.
  • Social engineering or phishing that does not exploit venmo-cli.
  • Vulnerabilities that require a user to intentionally provide an attacker with credentials or unrestricted access to an already unlocked account.

Vulnerabilities in Venmo or PayPal systems are outside this project's control and should be reported through their official security process. You may also notify this project privately when a CLI-side mitigation could protect venmo-cli users.

Safe research

  • Test only with accounts and data you own or have explicit permission to use.
  • Prefer --dry-run and non-mutating commands. Do not complete a real payment or transfer solely to demonstrate a vulnerability.
  • Do not access, retain, or disclose another person's data.
  • Do not disrupt Venmo, PayPal, this repository, or other users.
  • Stop testing if you encounter data or access outside your authorization.

There aren't any published security advisories

, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Strip utm_, fbclid, gclid, etc. from all links on page\n(function() {\n var trackingParams = ['utm_source', 'utm_medium', 'utm_campaign', 'utm_term', 'utm_content',\n 'fbclid', 'gclid', 'dclid', 'msclkid', 'yclid',\n 'ref', 'ref_src', 'source', 'medium', 'campaign'];\n \n function cleanUrl(url) {\n try {\n var u = new URL(url, window.location.origin);\n var changed = false;\n trackingParams.forEach(function(p) {\n if (u.searchParams.has(p)) {\n u.searchParams.delete(p);\n changed = true;\n }\n });\n return changed ? u.toString() : url;\n } catch (e) {\n return url;\n }\n }\n \n function cleanLinks() {\n document.querySelectorAll('a[href]').forEach(function(a) {\n var clean = cleanUrl(a.href);\n if (clean !== a.href) a.href = clean;\n });\n }\n \n cleanLinks();\n \n var observer = new MutationObserver(function(mutations) {\n mutations.forEach(function(m) {\n m.addedNodes.forEach(function(node) {\n if (node.nodeType === 1) {\n if (node.tagName === 'A') cleanLinks();\n node.querySelectorAll('a[href]').forEach(function(a) {\n var clean = cleanUrl(a.href);\n if (clean !== a.href) a.href = clean;\n });\n }\n });\n });\n });\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "Remove Tracking Parameters from Links"); } } catch(__e) { console.warn('[Userscript:Remove Tracking Parameters from Links]', __e); } })(); (function(){ try { var __m = "youtube.com"; var __re = new RegExp('^' + "youtube\\.com" + '
Skip to content

Security: jeph/venmo-cli

.github/SECURITY.md

Security Policy

Supported versions

venmo-cli is currently alpha software built on reverse-engineered, non-public Venmo endpoints. Only the latest published release receives security fixes.

VersionSecurity updates
Latest releaseSupported
Older releasesNot supported
Unreleased commitsNot supported

Before reporting a problem, reproduce it with the latest release when it is safe to do so.

Reporting a vulnerability

Do not disclose suspected vulnerabilities in a public issue, discussion, pull request, or social media post. Submit a private vulnerability report instead.

Include enough information to investigate without exposing private data:

  • The affected venmo-cli version, operating system, and CPU architecture.
  • The security impact and who could exploit it.
  • Minimal reproduction steps or a proof of concept.
  • Sanitized command output or debug diagnostics, if relevant.
  • Any suggested mitigation or fix.

Never include bearer tokens, v_id cookies, OTP codes, keyring contents, bank or card details, transaction identifiers, usernames, payment notes, amounts, or other personal or financial data. The maintainer will not ask you to provide authentication secrets.

Reports will be assessed privately. If the report is accepted, the maintainer will coordinate a fix, a release, and public disclosure as appropriate. Please allow time to investigate before publishing details. Reporters can be credited in a published advisory if they want attribution.

In scope

Examples of security issues in venmo-cli include:

  • Exposure or insecure storage of Venmo credentials or device identifiers.
  • Sensitive data appearing in normal output, JSON output, errors, or debug logs.
  • A way to bypass confirmation, --dry-run, funding-source selection, visibility, or other mutation safety controls.
  • Incorrect outcome handling that could make a financial mutation unsafe to retry.
  • Authentication or OTP handling that weakens account security.
  • Release artifact, signing, update, or packaging issues that could allow code substitution.
  • Local privilege or file-permission flaws caused by venmo-cli.

Out of scope

The following are not vulnerabilities in this project by themselves:

  • A non-public Venmo endpoint changing, disappearing, or rejecting a request.
  • Venmo service availability, rate limits, account policy, fees, or eligibility decisions.
  • Social engineering or phishing that does not exploit venmo-cli.
  • Vulnerabilities that require a user to intentionally provide an attacker with credentials or unrestricted access to an already unlocked account.

Vulnerabilities in Venmo or PayPal systems are outside this project's control and should be reported through their official security process. You may also notify this project privately when a CLI-side mitigation could protect venmo-cli users.

Safe research

  • Test only with accounts and data you own or have explicit permission to use.
  • Prefer --dry-run and non-mutating commands. Do not complete a real payment or transfer solely to demonstrate a vulnerability.
  • Do not access, retain, or disclose another person's data.
  • Do not disrupt Venmo, PayPal, this repository, or other users.
  • Stop testing if you encounter data or access outside your authorization.

There aren't any published security advisories

, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Auto-enable theater mode on YouTube\n(function() {\n function tryTheater() {\n var btn = document.querySelector('button[aria-label=\"Theater mode\"], ytd-player #player button[title=\"Theater mode\"]');\n if (btn && !btn.classList.contains('activated')) {\n btn.click();\n }\n }\n \n // Try immediately\n tryTheater();\n \n // Try after navigation (SPA)\n var lastUrl = location.href;\n setInterval(function() {\n if (location.href !== lastUrl) {\n lastUrl = location.href;\n setTimeout(tryTheater, 500);\n }\n }, 1000);\n \n // Also try on player load\n var observer = new MutationObserver(tryTheater);\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "YouTube Theater Mode Default"); } } catch(__e) { console.warn('[Userscript:YouTube Theater Mode Default]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

Security: jeph/venmo-cli

.github/SECURITY.md

Security Policy

Supported versions

venmo-cli is currently alpha software built on reverse-engineered, non-public Venmo endpoints. Only the latest published release receives security fixes.

VersionSecurity updates
Latest releaseSupported
Older releasesNot supported
Unreleased commitsNot supported

Before reporting a problem, reproduce it with the latest release when it is safe to do so.

Reporting a vulnerability

Do not disclose suspected vulnerabilities in a public issue, discussion, pull request, or social media post. Submit a private vulnerability report instead.

Include enough information to investigate without exposing private data:

  • The affected venmo-cli version, operating system, and CPU architecture.
  • The security impact and who could exploit it.
  • Minimal reproduction steps or a proof of concept.
  • Sanitized command output or debug diagnostics, if relevant.
  • Any suggested mitigation or fix.

Never include bearer tokens, v_id cookies, OTP codes, keyring contents, bank or card details, transaction identifiers, usernames, payment notes, amounts, or other personal or financial data. The maintainer will not ask you to provide authentication secrets.

Reports will be assessed privately. If the report is accepted, the maintainer will coordinate a fix, a release, and public disclosure as appropriate. Please allow time to investigate before publishing details. Reporters can be credited in a published advisory if they want attribution.

In scope

Examples of security issues in venmo-cli include:

  • Exposure or insecure storage of Venmo credentials or device identifiers.
  • Sensitive data appearing in normal output, JSON output, errors, or debug logs.
  • A way to bypass confirmation, --dry-run, funding-source selection, visibility, or other mutation safety controls.
  • Incorrect outcome handling that could make a financial mutation unsafe to retry.
  • Authentication or OTP handling that weakens account security.
  • Release artifact, signing, update, or packaging issues that could allow code substitution.
  • Local privilege or file-permission flaws caused by venmo-cli.

Out of scope

The following are not vulnerabilities in this project by themselves:

  • A non-public Venmo endpoint changing, disappearing, or rejecting a request.
  • Venmo service availability, rate limits, account policy, fees, or eligibility decisions.
  • Social engineering or phishing that does not exploit venmo-cli.
  • Vulnerabilities that require a user to intentionally provide an attacker with credentials or unrestricted access to an already unlocked account.

Vulnerabilities in Venmo or PayPal systems are outside this project's control and should be reported through their official security process. You may also notify this project privately when a CLI-side mitigation could protect venmo-cli users.

Safe research

  • Test only with accounts and data you own or have explicit permission to use.
  • Prefer --dry-run and non-mutating commands. Do not complete a real payment or transfer solely to demonstrate a vulnerability.
  • Do not access, retain, or disclose another person's data.
  • Do not disrupt Venmo, PayPal, this repository, or other users.
  • Stop testing if you encounter data or access outside your authorization.

There aren't any published security advisories

, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Remove or un-stick sticky/fixed headers that block content\n(function() {\n function unstick() {\n document.querySelectorAll('header, nav, [role=\"banner\"], .header, .navbar, .sticky, .fixed-top, [style*=\"position: fixed\"], [style*=\"position:sticky\"]').forEach(function(el) {\n if (el.style.position === 'fixed' || el.style.position === 'sticky' || \n getComputedStyle(el).position === 'fixed' || getComputedStyle(el).position === 'sticky') {\n el.style.position = 'static';\n el.style.top = 'auto';\n el.style.zIndex = 'auto';\n }\n });\n }\n \n unstick();\n \n var observer = new MutationObserver(unstick);\n observer.observe(document.body, { childList: true, subtree: true, attributes: true, attributeFilter: ['style', 'class'] });\n})();", "Kill Sticky Headers"); } } catch(__e) { console.warn('[Userscript:Kill Sticky Headers]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

Security: jeph/venmo-cli

.github/SECURITY.md

Security Policy

Supported versions

venmo-cli is currently alpha software built on reverse-engineered, non-public Venmo endpoints. Only the latest published release receives security fixes.

VersionSecurity updates
Latest releaseSupported
Older releasesNot supported
Unreleased commitsNot supported

Before reporting a problem, reproduce it with the latest release when it is safe to do so.

Reporting a vulnerability

Do not disclose suspected vulnerabilities in a public issue, discussion, pull request, or social media post. Submit a private vulnerability report instead.

Include enough information to investigate without exposing private data:

  • The affected venmo-cli version, operating system, and CPU architecture.
  • The security impact and who could exploit it.
  • Minimal reproduction steps or a proof of concept.
  • Sanitized command output or debug diagnostics, if relevant.
  • Any suggested mitigation or fix.

Never include bearer tokens, v_id cookies, OTP codes, keyring contents, bank or card details, transaction identifiers, usernames, payment notes, amounts, or other personal or financial data. The maintainer will not ask you to provide authentication secrets.

Reports will be assessed privately. If the report is accepted, the maintainer will coordinate a fix, a release, and public disclosure as appropriate. Please allow time to investigate before publishing details. Reporters can be credited in a published advisory if they want attribution.

In scope

Examples of security issues in venmo-cli include:

  • Exposure or insecure storage of Venmo credentials or device identifiers.
  • Sensitive data appearing in normal output, JSON output, errors, or debug logs.
  • A way to bypass confirmation, --dry-run, funding-source selection, visibility, or other mutation safety controls.
  • Incorrect outcome handling that could make a financial mutation unsafe to retry.
  • Authentication or OTP handling that weakens account security.
  • Release artifact, signing, update, or packaging issues that could allow code substitution.
  • Local privilege or file-permission flaws caused by venmo-cli.

Out of scope

The following are not vulnerabilities in this project by themselves:

  • A non-public Venmo endpoint changing, disappearing, or rejecting a request.
  • Venmo service availability, rate limits, account policy, fees, or eligibility decisions.
  • Social engineering or phishing that does not exploit venmo-cli.
  • Vulnerabilities that require a user to intentionally provide an attacker with credentials or unrestricted access to an already unlocked account.

Vulnerabilities in Venmo or PayPal systems are outside this project's control and should be reported through their official security process. You may also notify this project privately when a CLI-side mitigation could protect venmo-cli users.

Safe research

  • Test only with accounts and data you own or have explicit permission to use.
  • Prefer --dry-run and non-mutating commands. Do not complete a real payment or transfer solely to demonstrate a vulnerability.
  • Do not access, retain, or disclose another person's data.
  • Do not disrupt Venmo, PayPal, this repository, or other users.
  • Stop testing if you encounter data or access outside your authorization.

There aren't any published security advisories

, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Universal Dark Mode - works on any site\n(function() {\n var enabled = true;\n \n function applyDarkMode() {\n if (!enabled) return;\n \n // Create style element if it doesn't exist\n var style = document.getElementById('universal-dark-mode-style');\n if (!style) {\n style = document.createElement('style');\n style.id = 'universal-dark-mode-style';\n document.head.appendChild(style);\n }\n \n // Dark mode CSS - inverts colors but preserves images/video\n style.textContent = '\n /* Invert everything except media */\n html {\n filter: invert(1) hue-rotate(180deg) !important;\n background: #1a1a2e !important;\n }\n \n /* Restore images, videos, iframes, canvas */\n img, video, iframe, canvas, svg, picture, [style*=\"background-image\"] {\n filter: invert(1) hue-rotate(180deg) !important;\n }\n \n /* Preserve specific elements that should not be inverted */\n .no-dark-mode, .no-dark-mode *,\n [data-theme=\"light\"], [data-theme=\"light\"],\n .ace_editor, .ace_editor *,\n .CodeMirror, .CodeMirror *,\n .monaco-editor, .monaco-editor *,\n .markdown-body pre, .markdown-body pre *,\n .highlight, .highlight *,\n pre code, pre code * {\n filter: none !important;\n }\n \n /* Fix common UI elements */\n .modal, .popup, .dropdown-menu, .tooltip, .popover {\n filter: invert(1) hue-rotate(180deg) !important;\n background: #2d2d44 !important;\n border-color: #444 !important;\n }\n \n /* Scrollbars */\n ::-webkit-scrollbar { background: #1a1a2e !important; }\n ::-webkit-scrollbar-thumb { background: #444 !important; }\n ::-webkit-scrollbar-thumb:hover { background: #555 !important; }\n \n /* Selection */\n ::selection { background: #4ecdc4 !important; color: #1a1a2e !important; }\n ::-moz-selection { background: #4ecdc4 !important; color: #1a1a2e !important; }\n ';\n }\n \n function removeDarkMode() {\n var style = document.getElementById('universal-dark-mode-style');\n if (style) style.remove();\n }\n \n // Toggle with Alt+Shift+D\n document.addEventListener('keydown', function(e) {\n if (e.altKey && e.shiftKey && e.key === 'D') {\n e.preventDefault();\n enabled = !enabled;\n if (enabled) {\n applyDarkMode();\n console.log('[Universal Dark Mode] Enabled');\n } else {\n removeDarkMode();\n console.log('[Universal Dark Mode] Disabled');\n }\n }\n });\n \n // Apply on load\n applyDarkMode();\n \n // Re-apply on dynamic content\n var observer = new MutationObserver(function(mutations) {\n if (enabled && !document.getElementById('universal-dark-mode-style')) {\n applyDarkMode();\n }\n });\n observer.observe(document.head, { childList: true });\n \n console.log('[Universal Dark Mode] Loaded - Press Alt+Shift+D to toggle');\n})();", "Universal Dark Mode"); } } catch(__e) { console.warn('[Userscript:Universal Dark Mode]', __e); } })(); })();
Skip to content

Security: jeph/venmo-cli

.github/SECURITY.md

Security Policy

Supported versions

venmo-cli is currently alpha software built on reverse-engineered, non-public Venmo endpoints. Only the latest published release receives security fixes.

VersionSecurity updates
Latest releaseSupported
Older releasesNot supported
Unreleased commitsNot supported

Before reporting a problem, reproduce it with the latest release when it is safe to do so.

Reporting a vulnerability

Do not disclose suspected vulnerabilities in a public issue, discussion, pull request, or social media post. Submit a private vulnerability report instead.

Include enough information to investigate without exposing private data:

  • The affected venmo-cli version, operating system, and CPU architecture.
  • The security impact and who could exploit it.
  • Minimal reproduction steps or a proof of concept.
  • Sanitized command output or debug diagnostics, if relevant.
  • Any suggested mitigation or fix.

Never include bearer tokens, v_id cookies, OTP codes, keyring contents, bank or card details, transaction identifiers, usernames, payment notes, amounts, or other personal or financial data. The maintainer will not ask you to provide authentication secrets.

Reports will be assessed privately. If the report is accepted, the maintainer will coordinate a fix, a release, and public disclosure as appropriate. Please allow time to investigate before publishing details. Reporters can be credited in a published advisory if they want attribution.

In scope

Examples of security issues in venmo-cli include:

  • Exposure or insecure storage of Venmo credentials or device identifiers.
  • Sensitive data appearing in normal output, JSON output, errors, or debug logs.
  • A way to bypass confirmation, --dry-run, funding-source selection, visibility, or other mutation safety controls.
  • Incorrect outcome handling that could make a financial mutation unsafe to retry.
  • Authentication or OTP handling that weakens account security.
  • Release artifact, signing, update, or packaging issues that could allow code substitution.
  • Local privilege or file-permission flaws caused by venmo-cli.

Out of scope

The following are not vulnerabilities in this project by themselves:

  • A non-public Venmo endpoint changing, disappearing, or rejecting a request.
  • Venmo service availability, rate limits, account policy, fees, or eligibility decisions.
  • Social engineering or phishing that does not exploit venmo-cli.
  • Vulnerabilities that require a user to intentionally provide an attacker with credentials or unrestricted access to an already unlocked account.

Vulnerabilities in Venmo or PayPal systems are outside this project's control and should be reported through their official security process. You may also notify this project privately when a CLI-side mitigation could protect venmo-cli users.

Safe research

  • Test only with accounts and data you own or have explicit permission to use.
  • Prefer --dry-run and non-mutating commands. Do not complete a real payment or transfer solely to demonstrate a vulnerability.
  • Do not access, retain, or disclose another person's data.
  • Do not disrupt Venmo, PayPal, this repository, or other users.
  • Stop testing if you encounter data or access outside your authorization.

There aren't any published security advisories