PostHog Server-Side Request Forgery Vulnerability Allowing Information Disclosure

Vulnerability

A server-side request forgery (SSRF) vulnerability has been identified in PostHog, specifically within the 'database_schema' method. This vulnerability arises from inadequate validation of URIs before accessing resources, enabling authenticated remote attackers to disclose sensitive information in the context of the service account.

Impact

Exploitation of this vulnerability could lead to unauthorized information disclosure from the PostHog database.

Remediation

PostHog has released a patch for this vulnerability. Users should update to the latest version.

Added: Jun 9, 2025, 7:46 PM
Updated: Jun 9, 2025, 7:46 PM

Vulnerability Rating

Custom Algorithm
spread
3.1
impact
2.5
exploitability
5.9
remediation
7.7
relevance
0.0
threat
3.2
urgency
2.9
incentive
1.7

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.