T09 · Insecure Skill Coding Practices
- Location
scripts/posthog.sh:14- Finding
Unvalidated API Host Configuration Can Expose PostHog Credentials
- Content
View full analysis
[propertiesJson]" >&2; exit 1; } props="${3:-{}}" curl -sf -H "$CT" -X POST -d "{\"api_key\":\"$PROJECT_KEY\",\"event\":\"$1\",\"distinct_id\":\"$2\",\"properties\":$props}" "$INGEST/i/v0/e/" ;; ``` ```bash evaluate-flags) _project_key_check [[ -z "${1:-}" ]] && { echo "Usage: posthog.sh evaluate-flags [groupsJson]" >&2; exit 1; } groups="${2:-{}}" curl -sf -H "$CT" -X POST -d "{\"api_key\":\"$PROJECT_KEY\",\"distinct_id\":\"$1\",\"groups\":$groups}" "$INGEST/flags?v=2" ;; ``` ```bash whoami) _auth_check _get "$HOST/api/users/@me/" ;; ``` ### Technical Analysis The script accepts `POSTHOG_HOST` and `POSTHOG_INGEST_HOST` directly from environment variables without validating their schemes or destinations. Private API helper functions unconditionally add the personal API key as an `Authorization: Bearer` header. Consequently, setting `POSTHOG_HOST` to an attacker-controlled server causes commands such as `whoami`, `query`, or resource-listing operations to transmit the personal API key to that server. Public ingestion commands place `POSTHOG_PROJECT_API_KEY` directly in JSON request bodies sent to `POSTHOG_INGEST_HOST`. An attacker-controlled ingest host ...[truncated 2733 chars]- Remediation
View remediation
&2 exit 1 ;; esac } _validate_https_host "$HOST" _validate_https_host "$INGEST" ``` For self-hosted installations, replace the fixed allowlist with a carefully validated administrator-controlled allowlis ...[truncated 64 chars]
