CVE-2023-32325: Cross-site scripting in PostHog-js
Impact
Potential for cross-site scripting in posthog-js.
Patches
The problem has been patched in posthog-js version 1.57.2.
Workarounds
- This isn't an issue for sites that have a Content Security Policy in place. - Using the HTML tracking snippet on PostHog Cloud always guarantees the latest version of the library – in that case no action is required to upgrade to the patched version.
References
We will publish details of the vulnerability in 30 days as per our security policy.
Other sources
PostHog-js is a library to interface with the PostHog analytics tool. Versions prior to 1.57.2 have the potential for cross-site scripting. Problem has been patched in 1.57.2. Users are advised to upgrade. Users unable to upgrade should ensure that their Content Security Policy is in place.
— MITRE
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the vulnerability ID for this issue?
The vulnerability ID for this issue is CVE-2023-32325.
What is the impact of this vulnerability?
This vulnerability has the potential for cross-site scripting in `posthog-js`.
How can I fix this vulnerability?
To fix this vulnerability, update `posthog-js` to version 1.57.2 or later.
Are there any workarounds for this vulnerability?
Yes, you can mitigate this vulnerability by implementing a Content Security Policy.
What is the severity level of this vulnerability?
The severity level of this vulnerability is medium (6.1).