CVE-2025-1521

CVSS 3.0 Score 7.1 of 10 (high)

Details

Published Apr 23, 2025
Updated: Apr 29, 2025
CWE ID 918

Summary

CVE-2025-1521 is a Server-Side Request Forgery (SSRF) Information Disclosure vulnerability affecting PostHog's slack_incoming_webhook feature. This issue enables remote attackers to access sensitive information on vulnerable installations of PostHog, requiring authentication to exploit it. The root cause is the inadequate validation of a URI before accessing resources. An attacker can exploit this flaw to execute code using the service account's privileges. (ZDI-CAN-25352)

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share