GHSA-8775-5hwv-wr6v

Source
https://github.com/advisories/GHSA-8775-5hwv-wr6v
Import Source
https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2023/05/GHSA-8775-5hwv-wr6v/GHSA-8775-5hwv-wr6v.json
Aliases
Published
2023-05-22T20:35:03Z
Modified
2023-11-08T04:12:34.903044Z
Details

Impact

Potential for cross-site scripting in posthog-js.

Patches

The problem has been patched in posthog-js version 1.57.2.

Workarounds

  • This isn't an issue for sites that have a Content Security Policy in place.
  • Using the HTML tracking snippet on PostHog Cloud always guarantees the latest version of the library – in that case no action is required to upgrade to the patched version.

References

We will publish details of the vulnerability in 30 days as per our security policy.

References

Affected packages

npm / posthog-js

Package

Affected ranges

Type
SEMVER
Events
Introduced
0The exact introduced commit is unknown
Fixed
1.57.2