CVE-2023-32325: Posthog Posthog-Js

Medium severity, CVSS 6.1. EPSS: 0.4% chance of exploitation in the next 30 days.

PostHog-js is a library to interface with the PostHog analytics tool. Versions prior to 1.57.2 have the potential for cross-site scripting. Problem has been patched in 1.57.2. Users are advised to upgrade. Users unable to upgrade should ensure that their Content Security Policy is in place.

Affected products

  • Posthog Posthog-Js: before 1.57.2 (fixed in 1.57.2)

Published 2023-05-27. Last modified 2026-06-17.