PT-2026-48683 · Npm+2 · @Element-Hq/Element-Call-Embedded+1
CVE-2026-48007
·
Published
2026-06-11
·
Updated
2026-08-07
CVSS v4.0
8.6
High
| Vector | AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N |
Name of the Vulnerable Software and Affected Versions
Element Call versions 0.5.17 through 0.19.3
Description
Element Call reports analytics data to a PostHog server when configured via a
posthog key in config.json or through the posthogApiHost and posthogApiKey URL parameters. The fields $initial person info, $session entry url, and $current url contain the full URL of the visited page, including the fragment. In standalone Single Page Application (SPA) instances, this can lead to the reporting of full call URLs, including encryption passwords, to the PostHog server. This potentially compromises call confidentiality if an actor has access to both the analytics data and the encrypted media streams. While the embedded package is also affected, it does not impact applications like Element Web, Element Desktop, Element X iOS, and Element X Android because they distribute encryption keys over Matrix instead of encoding passwords in the URL.Recommendations
Update to version 0.19.4.
Users can opt out of analytics in the Feedback tab of the settings and create new links for future calls.
Admins hosting standalone applications can disable PostHog analytics by removing the
posthog key from the config.json file.Exploit
Fix
Information Disclosure
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
@Element-Hq/Element-Call-Embedded
Element-Call