BugCrowd Bug Bounty Disclosure: P4 – Members can enumerate and delete organization invites –

Members can enumerate and delete organization invites

Members can enumerate and delete organization invites

Researcher:
Engagement: PostHog Vulnerability Disclosure Engagement
Disclosed at: 2025-09-18T17:09:45Z
Priority: P4
Status: Resolved

Summary

Members always have the ability to list invites. Our backend additionally allowed them to delete invites, but our frontend prevented this. After discussing internally, we decided to honor the frontend logic and have adjusted our backend to disallow Members from deleting invites.

https://github.com/PostHog/posthog/pull/38256

Activity Feed

Actor Details Timestamp (UTC)
a Crowdcontrol user a Crowdcontrol user published 2025-09-18T17:09:45Z
a Crowdcontrol user a Crowdcontrol user sent a: message 2025-09-18T17:07:25Z
_x3ro_ _x3ro_ requested 2025-09-18T06:14:18Z
a Crowdcontrol user a Crowdcontrol user changed the state to to resolved 2025-09-18T01:05:52Z
a Crowdcontrol user a Crowdcontrol user sent a: message 2025-09-18T01:05:46Z
a Crowdcontrol user a Crowdcontrol user changed the state to to unresolved 2025-09-18T01:04:20Z
a Crowdcontrol user a Crowdcontrol user created a blocker on 2025-09-17T19:58:52Z
Parker_Bugcrowd Parker_Bugcrowd changed the severity to 2025-09-16T19:38:26Z
Parker_Bugcrowd Parker_Bugcrowd sent a: message 2025-09-16T19:38:17Z
Parker_Bugcrowd Parker_Bugcrowd changed the state to to triaged 2025-09-16T19:38:16Z
_x3ro_ _x3ro_ resolved a blocker for 2025-09-16T04:09:02Z
_x3ro_ _x3ro_ sent a: message 2025-09-16T04:09:01Z
Glitch_Bugcrowd Glitch_Bugcrowd sent a: message 2025-09-15T20:21:16Z
Glitch_Bugcrowd Glitch_Bugcrowd created a blocker on 2025-09-15T20:21:15Z
_x3ro_ _x3ro_ created the submission 2025-09-12T12:18:32Z

A considerable amount of time and effort goes into maintaining this website, creating backend automation and creating new features and content for you to make actionable intelligence decisions. Everyone that supports the site helps enable new functionality.

If you like the site, please support us on “Patreon” or “Buy Me A Coffee” using the buttons below

To keep up to date follow us on the below channels.