PostHog-js is a library to interface with the PostHog analytics tool. Versions prior to 1.57.2 have the potential for cross-site scripting. Problem has been patched in 1.57.2. Users are advised to upgrade. Users unable to upgrade should ensure that their Content Security Policy is in place.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2023-1501 | PostHog-js is a library to interface with the PostHog analytics tool. Versions prior to 1.57.2 have the potential for cross-site scripting. Problem has been patched in 1.57.2. Users are advised to upgrade. Users unable to upgrade should ensure that their Content Security Policy is in place. |
Github GHSA |
GHSA-8775-5hwv-wr6v | Potential for cross-site scripting in PostHog-js |
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
Tue, 14 Jan 2025 19:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2025-01-14T18:40:43.462Z
Reserved: 2023-05-08T13:26:03.880Z
Link: CVE-2023-32325
Updated: 2024-08-02T15:10:24.912Z
Status : Modified
Published: 2023-05-27T00:15:09.600
Modified: 2024-11-21T08:03:07.090
Link: CVE-2023-32325
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD
Github GHSA