Inside PostHog: SSRF, ClickHouse SQL Escape and Default Postgres Creds to RCE
arwt Wednesday, December 17, 2025
Summary
The article describes a vulnerability chain in the PostHog application, involving Server-Side Request Forgery (SSRF), a ClickHouse SQL injection vulnerability, and default PostgreSQL credentials, ultimately leading to Remote Code Execution (RCE). The vulnerabilities were discovered and reported through the Zero Day Initiative (ZDI).
88
23
Summary
mdisec.com