Executive brief
PostHog's JavaScript tracking library (posthog-js) contains a cross-site scripting (XSS) vulnerability that could allow an attacker with low-level privileges to inject malicious scripts into web pages that use the library. An attacker could steal user data, session tokens, or perform actions on behalf of users viewing the affected page. The vulnerability requires user interaction and does not affect sites with proper Content Security Policies in place.
Technical details
PostHog-js versions prior to 1.57.2 are vulnerable to stored or DOM-based cross-site scripting (CWE-79) through improper input sanitization or unsafe DOM manipulation. The vulnerability has a CVSS v3.1 score of 5.4 (Medium) with network attack vector, low complexity, and requires low privileges and user interaction. An attacker can craft malicious input that, when processed by posthog-js, results in JavaScript execution in the victim's browser context, potentially compromising confidentiality and integrity of the page. The vulnerability has been patched in version 1.57.2, and organizations can mitigate risk by implementing strict Content Security Policies or using PostHog Cloud's hosted snippet which auto-updates.
Affected products
- PostHog posthog-js < 1.57.2
Timeline
- 2023-05-22: disclosed: Vulnerability disclosed on GitHub Security Advisory GHSA-8775-5hwv-wr6v
- 2023-05-22: patched: Fixed in posthog-js version 1.57.2