Hasty Briefsbeta

Bilingual

You click a PostHog survey. An attacker gets your whole account

a day ago
  • Strix, an AI security agent, discovered an XSS vulnerability in PostHog's survey feature where the introduction screen description field was not sanitized, allowing arbitrary JavaScript injection.
  • An attacker could create a survey link on the PostHog domain; when a signed-in user opened it, the injected JavaScript could steal personal API keys with maximum scope, compromising the account.
  • PostHog quickly fixed the issue by sanitizing the new field and sandboxing hosted surveys without allow-same-origin, and later implemented a strict CSP to prevent unsafe inline JavaScript.
  • The vulnerability was missed by several security scanners (CodeQL, Semgrep, Wiz tools) that passed, highlighting the need for thorough code review.
  • PostHog confirmed the issue was never exploited outside of Strix's tests and worked collaboratively on disclosure and remediation.