You click a PostHog survey. An attacker gets your whole account
a day ago
- Strix, an AI security agent, discovered an XSS vulnerability in PostHog's survey feature where the introduction screen description field was not sanitized, allowing arbitrary JavaScript injection.
- An attacker could create a survey link on the PostHog domain; when a signed-in user opened it, the injected JavaScript could steal personal API keys with maximum scope, compromising the account.
- PostHog quickly fixed the issue by sanitizing the new field and sandboxing hosted surveys without allow-same-origin, and later implemented a strict CSP to prevent unsafe inline JavaScript.
- The vulnerability was missed by several security scanners (CodeQL, Semgrep, Wiz tools) that passed, highlighting the need for thorough code review.
- PostHog confirmed the issue was never exploited outside of Strix's tests and worked collaboratively on disclosure and remediation.