PT-2026-48683 · Npm+2 · @Element-Hq/Element-Call-Embedded+1

CVE-2026-48007

·

Published

2026-06-11

·

Updated

2026-08-07

CVSS v4.0

8.6

High

VectorAV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions Element Call versions 0.5.17 through 0.19.3
Description Element Call reports analytics data to a PostHog server when configured via a posthog key in config.json or through the posthogApiHost and posthogApiKey URL parameters. The fields $initial person info, $session entry url, and $current url contain the full URL of the visited page, including the fragment. In standalone Single Page Application (SPA) instances, this can lead to the reporting of full call URLs, including encryption passwords, to the PostHog server. This potentially compromises call confidentiality if an actor has access to both the analytics data and the encrypted media streams. While the embedded package is also affected, it does not impact applications like Element Web, Element Desktop, Element X iOS, and Element X Android because they distribute encryption keys over Matrix instead of encoding passwords in the URL.
Recommendations Update to version 0.19.4. Users can opt out of analytics in the Feedback tab of the settings and create new links for future calls. Admins hosting standalone applications can disable PostHog analytics by removing the posthog key from the config.json file.

Exploit

Fix

Information Disclosure

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-48007
GHSA-6VHH-4XW6-H2H2

Affected Products

@Element-Hq/Element-Call-Embedded
Element-Call