Here's the PR that introduced the vulnerability: https://github.com/PostHog/posthog/pull/37915
It's a bit funny the vuln was introduced by someone with the username "haacked"