CVE-2025-1522
CVSS 3.0 Score 7.1 of 10 (high)
Details
Published Apr 23, 2025
Updated: Apr 29, 2025
CWE ID 918
Summary
CVE-2025-1522 is a Server-Side Request Forgery (SSRF) vulnerability affecting PostHog's database_schema function. This issue allows remote attackers, who have obtained authentication credentials, to disclose sensitive information from affected installations. The root cause of this vulnerability lies in insufficient URI validation, allowing an attacker to access restricted resources and leak data in the context of the service account (Previously identified as ZDI-CAN-25358).
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.