Ecosyste.ms: Advisories

An open API service providing security vulnerability metadata for many open source software ecosystems.

Security Advisories: GSA_kwCzR0hTQS04Nzc1LTVod3Ytd3I2ds4AAzbF

Potential for cross-site scripting in PostHog-js

Impact

Potential for cross-site scripting in posthog-js.

Patches

The problem has been patched in posthog-js version 1.57.2.

Workarounds

References

We will publish details of the vulnerability in 30 days as per our security policy.

Permalink: https://github.com/advisories/GHSA-8775-5hwv-wr6v
JSON: https://advisories.ecosyste.ms/api/v1/advisories/GSA_kwCzR0hTQS04Nzc1LTVod3Ytd3I2ds4AAzbF
Source: GitHub Advisory Database
Origin: Unspecified
Severity: Moderate
Classification: General
Published: 12 months ago
Updated: 6 months ago


CVSS Score: 5.4
CVSS vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N

Identifiers: GHSA-8775-5hwv-wr6v, CVE-2023-32325
References: Repository: https://github.com/PostHog/posthog-js
Blast Radius: 18.5

Affected Packages

npm:posthog-js
Dependent packages: 92
Dependent repositories: 2,707
Downloads: 1,967,200 last month
Affected Version Ranges: < 1.57.2
Fixed in: 1.57.2
All affected versions: 1.0.0, 1.0.1, 1.0.2, 1.0.3, 1.0.4, 1.0.5, 1.0.6, 1.1.0, 1.1.1, 1.1.2, 1.2.0, 1.2.1, 1.2.2, 1.2.3, 1.2.4, 1.3.0, 1.3.1, 1.3.2, 1.3.3, 1.3.4, 1.3.5, 1.3.6, 1.3.7, 1.3.8, 1.4.0, 1.4.1, 1.4.2, 1.4.3, 1.4.4, 1.4.5, 1.5.0, 1.5.1, 1.5.2, 1.6.0, 1.7.0, 1.7.1, 1.7.2, 1.8.0, 1.8.3, 1.8.5, 1.8.6, 1.8.7, 1.8.8, 1.8.9, 1.8.10, 1.9.0, 1.9.1, 1.9.2, 1.9.3, 1.9.4, 1.9.5, 1.9.6, 1.9.7, 1.10.0, 1.10.1, 1.10.2, 1.11.0, 1.11.1, 1.11.2, 1.11.3, 1.11.4, 1.12.0, 1.12.1, 1.12.2, 1.12.3, 1.12.4, 1.12.5, 1.12.6, 1.12.7, 1.13.0, 1.13.1, 1.13.2, 1.13.3, 1.13.4, 1.13.5, 1.13.6, 1.13.7, 1.13.8, 1.13.9, 1.13.10, 1.13.11, 1.13.12, 1.13.13, 1.13.14, 1.13.15, 1.13.16, 1.13.17, 1.14.0, 1.14.1, 1.14.2, 1.14.3, 1.14.4, 1.14.5, 1.15.0, 1.15.1, 1.15.2, 1.15.3, 1.15.4, 1.16.0, 1.16.1, 1.16.2, 1.16.3, 1.16.4, 1.16.5, 1.16.6, 1.16.7, 1.16.8, 1.17.0, 1.17.1, 1.17.2, 1.17.3, 1.17.4, 1.17.5, 1.17.6, 1.17.7, 1.17.8, 1.17.9, 1.18.0, 1.19.0, 1.19.1, 1.19.2, 1.20.0, 1.20.1, 1.20.2, 1.20.3, 1.20.4, 1.20.5, 1.21.0, 1.21.1, 1.22.0, 1.23.0, 1.24.0, 1.25.0, 1.25.1, 1.25.2, 1.26.0, 1.26.1, 1.26.2, 1.27.0, 1.28.0, 1.29.0, 1.29.1, 1.29.2, 1.29.3, 1.30.0, 1.31.0, 1.31.1, 1.32.0, 1.32.1, 1.32.2, 1.32.3, 1.32.4, 1.33.0, 1.34.0, 1.34.1, 1.35.0, 1.36.0, 1.36.1, 1.37.0, 1.38.0, 1.38.1, 1.39.0, 1.39.1, 1.39.2, 1.39.3, 1.39.4, 1.39.5, 1.40.0, 1.40.1, 1.40.2, 1.41.0, 1.42.0, 1.42.1, 1.42.2, 1.42.3, 1.43.0, 1.43.1, 1.44.0, 1.45.0, 1.45.1, 1.46.0, 1.46.1, 1.46.2, 1.47.0, 1.48.0, 1.48.1, 1.48.2, 1.49.0, 1.50.0, 1.50.1, 1.50.2, 1.50.3, 1.50.4, 1.50.5, 1.50.6, 1.50.7, 1.50.8, 1.50.9, 1.51.0, 1.51.1, 1.51.2, 1.51.3, 1.51.4, 1.51.5, 1.52.0, 1.53.0, 1.53.1, 1.53.2, 1.53.3, 1.53.4, 1.54.0, 1.55.0, 1.55.1, 1.55.2, 1.56.0, 1.57.0, 1.57.1
All unaffected versions: 1.57.2, 1.57.3, 1.57.4, 1.58.0, 1.59.0, 1.60.0, 1.61.0, 1.62.0, 1.63.0, 1.63.1, 1.63.2, 1.63.3, 1.63.4, 1.63.5, 1.63.6, 1.64.0, 1.65.0, 1.66.0, 1.66.1, 1.67.0, 1.67.1, 1.68.0, 1.68.1, 1.68.2, 1.68.3, 1.68.4, 1.68.5, 1.69.0, 1.70.0, 1.70.1, 1.70.2, 1.71.0, 1.72.0, 1.72.1, 1.72.2, 1.72.3, 1.73.0, 1.73.1, 1.74.0, 1.75.0, 1.75.1, 1.75.2, 1.75.3, 1.75.4, 1.76.0, 1.77.0, 1.77.1, 1.77.2, 1.77.3, 1.78.0, 1.78.1, 1.78.2, 1.78.3, 1.78.4, 1.78.5, 1.78.6, 1.79.0, 1.79.1, 1.80.0, 1.81.0, 1.81.1, 1.81.2, 1.81.3, 1.81.4, 1.82.0, 1.82.1, 1.82.2, 1.82.3, 1.83.0, 1.83.1, 1.83.2, 1.83.3, 1.84.0, 1.84.1, 1.84.2, 1.84.3, 1.84.4, 1.85.0, 1.85.1, 1.85.2, 1.85.3, 1.85.4, 1.86.0, 1.87.0, 1.87.1, 1.87.2, 1.87.3, 1.87.4, 1.87.5, 1.87.6, 1.88.0, 1.88.1, 1.88.2, 1.88.3, 1.88.4, 1.89.0, 1.89.1, 1.89.2, 1.90.0, 1.90.1, 1.90.2, 1.91.0, 1.91.1, 1.92.0, 1.92.1, 1.93.0, 1.93.1, 1.93.2, 1.93.3, 1.93.4, 1.93.5, 1.93.6, 1.94.0, 1.94.1, 1.94.2, 1.94.3, 1.94.4, 1.95.0, 1.95.1, 1.96.0, 1.96.1, 1.97.0, 1.97.1, 1.98.0, 1.98.1, 1.98.2, 1.99.0, 1.100.0, 1.101.0, 1.102.0, 1.102.1, 1.103.0, 1.103.1, 1.103.2, 1.104.0, 1.104.1, 1.104.2, 1.104.3, 1.104.4, 1.105.0, 1.105.1, 1.105.2, 1.105.3, 1.105.4, 1.105.5, 1.105.6, 1.105.7, 1.105.8, 1.105.9, 1.106.0, 1.106.1, 1.106.2, 1.106.3, 1.107.0, 1.108.0, 1.108.1, 1.108.2, 1.108.3, 1.108.4, 1.109.0, 1.110.0, 1.111.0, 1.111.1, 1.111.2, 1.111.3, 1.112.0, 1.112.1, 1.113.0, 1.113.1, 1.113.2, 1.113.3, 1.113.4, 1.114.0, 1.114.1, 1.114.2, 1.115.0, 1.115.1, 1.115.2, 1.116.0, 1.116.1, 1.116.2, 1.116.3, 1.116.4, 1.116.5, 1.116.6, 1.116.7, 1.117.0, 1.117.1, 1.117.2, 1.118.0, 1.118.1, 1.119.0, 1.119.1, 1.119.2, 1.120.0, 1.120.1, 1.120.2, 1.120.3, 1.120.4, 1.120.5, 1.121.0, 1.121.1, 1.121.2, 1.121.3, 1.121.4, 1.122.0, 1.123.0, 1.123.1, 1.124.0, 1.125.0, 1.126.0, 1.127.0, 1.128.0, 1.128.1, 1.128.2, 1.128.3, 1.128.4, 1.128.5, 1.129.0, 1.130.0, 1.130.1, 1.130.2, 1.131.0, 1.131.1, 1.131.2, 1.131.3