logoalt Hacker News

nightpoollast Wednesday at 11:10 PM1 replyview on HN

It looks like the entire class of bugs here are "if you have access to Posthog's admin dashboard, you can configure webhook URLs that hit Posthog's internal services". That's not particularly surprising for a self-hosted system like the author's, but I expect it would pretty bad if you were using their cloud-hosted product.


Replies

anothercatlast Thursday at 7:25 AM

Ah of couse! I forgot about the cloud hosted option.

show 1 reply