Web Hack List

Collected research

Inside PostHog: How SSRF, a ClickHouse SQL Escaping 0day, and Default PostgreSQL Credentials Formed an RCE Chain

Chains a PostHog webhook validation gap into persistent SSRF against its internal ClickHouse HTTP API. Incorrect PostgreSQL escaping in a ClickHouse table function permits SQL injection, and PostHog's default database credentials turn the cross-service chain into remote code execution.

Record

Researcher
Mehmet Ince
Published by
Mehmet Ince @mdisec - Vulnerability Researcher | Building security products | Security Advisor | Amateur Muay Thai fighter
Date

In the archive

Tags

This page is the archive's own catalogue record. The research is the work of Mehmet Ince, first published at the original source. Preserved copies are kept so the citation survives its host.