Collected research
Inside PostHog: How SSRF, a ClickHouse SQL Escaping 0day, and Default PostgreSQL Credentials Formed an RCE Chain
Chains a PostHog webhook validation gap into persistent SSRF against its internal ClickHouse HTTP API. Incorrect PostgreSQL escaping in a ClickHouse table function permits SQL injection, and PostHog's default database credentials turn the cross-service chain into remote code execution.
Record
- Researcher
- Mehmet Ince
- Published by
- Mehmet Ince @mdisec - Vulnerability Researcher | Building security products | Security Advisor | Amateur Muay Thai fighter
- Date
In the archive
Tags
This page is the archive's own catalogue record. The research is the work of Mehmet Ince, first published at the original source. Preserved copies are kept so the citation survives its host.