v0.35.2

PostHog/posthog.comv0.35.2Aug 31, 2026by github-actions[bot]

AI Summary

A security-focused update that hardens dashboard origin validation and reverse-proxy access to defend against DNS rebinding and smuggling attacks, alongside a fix for CDP WebSocket URL handling.

Key Highlights

  • Hardened dashboard origin validation and reverse-proxy access
  • Defense against DNS rebinding, form/header smuggling, and cross-origin requests
  • Fixed root remote CDP WebSocket URLs with query strings

Full Release Notes

### Security

- Hardened **dashboard origin validation and reverse-proxy access** with same-origin provenance enforcement that defends against DNS rebinding, form/header smuggling, and cross-origin requests. Reverse-proxied origins now require exact HTTPS allowlisting and generated token authentication, while tokenless IPv4 and IPv6 loopback access remains supported. Dashboard options are validated strictly, and CLI and MCP lifecycle behavior is aligned (#1738)

### Bug Fixes

- Fixed **root remote CDP WebSocket URLs with query strings** to insert the required slash before the query while preserving the encoded query (#1735)

### Contributors

- @ctate
- @Railly