CVE-2026-48007: CWE-200: Exposure of Sensitive Information to an Unauthorized Actor in element-hq element-call
Element Call is a native Matrix video conferencing application. Versions 0.5.17 through 0.19.3 report analytics data to a PostHog server, when configured to by a `posthog` key in config.json or by the `posthogApiHost` and `posthogApiKey` URL parameters. Several fields of this data (`$initial_person_info`, `$session_entry_url`, and `$current_url`) were found to contain the full URL of the user's visited page, including the fragment. Users of a standalone Element Call ‘SPA’ instance such as https://call.element.io may therefore have reported the full URLs of certain calls, including encryption passwords, to the configured PostHog server, potentially compromising the confidentiality of the calls to actors who could access both the PostHog analytics data and the encrypted media streams. The same issue is present in Element Call's embedded package, but in practice it does not impact applications using this package (including Element Web, Element Desktop, Element X iOS, and Element X Android) because they distribute encryption keys over Matrix rather than encoding a password in the URL. The issue is patched in Element Call 0.19.4. Some workarounds are available. Users may opt out of analytics in the 'Feedback' tab of Element Call's settings and create new links for future calls. Admins who host Element Call as a standalone application may disable PostHog analytics entirely by removing the `posthog` key from their deployment's config.json file.
AI Analysis
Technical Summary
Element Call, a native Matrix video conferencing application, versions 0.5.17 through 0.19.3 report analytics data to a PostHog server when configured. Several fields in this data include the full URL of the user's visited page, including URL fragments that may contain encryption passwords. This leads to exposure of sensitive information to unauthorized actors who can access both the PostHog analytics data and encrypted media streams. Embedded packages of Element Call are not impacted in practice due to different encryption key distribution methods. The vulnerability is fixed in Element Call 0.19.4. Workarounds include opting out of analytics and disabling PostHog analytics in config.json.
Potential Impact
Sensitive information including encryption passwords embedded in URLs may be exposed to unauthorized actors with access to the PostHog analytics server, potentially compromising the confidentiality of encrypted calls. This affects standalone Element Call SPA instances configured to report analytics. Embedded Element Call packages in other Element products are not practically impacted. The vulnerability has a high severity with a CVSS 4.0 score of 8.6.
Mitigation Recommendations
A fix is available in Element Call version 0.19.4. Users should upgrade to this version to eliminate the vulnerability. Alternatively, users can opt out of analytics reporting via the 'Feedback' tab in Element Call settings. Administrators hosting standalone Element Call instances can disable PostHog analytics entirely by removing the 'posthog' key from the deployment's config.json file. These mitigations prevent sensitive URL data from being sent to the analytics server.
CVE-2026-48007: CWE-200: Exposure of Sensitive Information to an Unauthorized Actor in element-hq element-call
Description
Element Call is a native Matrix video conferencing application. Versions 0.5.17 through 0.19.3 report analytics data to a PostHog server, when configured to by a `posthog` key in config.json or by the `posthogApiHost` and `posthogApiKey` URL parameters. Several fields of this data (`$initial_person_info`, `$session_entry_url`, and `$current_url`) were found to contain the full URL of the user's visited page, including the fragment. Users of a standalone Element Call ‘SPA’ instance such as https://call.element.io may therefore have reported the full URLs of certain calls, including encryption passwords, to the configured PostHog server, potentially compromising the confidentiality of the calls to actors who could access both the PostHog analytics data and the encrypted media streams. The same issue is present in Element Call's embedded package, but in practice it does not impact applications using this package (including Element Web, Element Desktop, Element X iOS, and Element X Android) because they distribute encryption keys over Matrix rather than encoding a password in the URL. The issue is patched in Element Call 0.19.4. Some workarounds are available. Users may opt out of analytics in the 'Feedback' tab of Element Call's settings and create new links for future calls. Admins who host Element Call as a standalone application may disable PostHog analytics entirely by removing the `posthog` key from their deployment's config.json file.
CVSS v4.0
Score 8.6high
Affected software
element-hq
element-call
pkg:github/element-hq/element-callRun on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.
Weaknesses
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
Element Call, a native Matrix video conferencing application, versions 0.5.17 through 0.19.3 report analytics data to a PostHog server when configured. Several fields in this data include the full URL of the user's visited page, including URL fragments that may contain encryption passwords. This leads to exposure of sensitive information to unauthorized actors who can access both the PostHog analytics data and encrypted media streams. Embedded packages of Element Call are not impacted in practice due to different encryption key distribution methods. The vulnerability is fixed in Element Call 0.19.4. Workarounds include opting out of analytics and disabling PostHog analytics in config.json.
Potential Impact
Sensitive information including encryption passwords embedded in URLs may be exposed to unauthorized actors with access to the PostHog analytics server, potentially compromising the confidentiality of encrypted calls. This affects standalone Element Call SPA instances configured to report analytics. Embedded Element Call packages in other Element products are not practically impacted. The vulnerability has a high severity with a CVSS 4.0 score of 8.6.
Mitigation Recommendations
A fix is available in Element Call version 0.19.4. Users should upgrade to this version to eliminate the vulnerability. Alternatively, users can opt out of analytics reporting via the 'Feedback' tab in Element Call settings. Administrators hosting standalone Element Call instances can disable PostHog analytics entirely by removing the 'posthog' key from the deployment's config.json file. These mitigations prevent sensitive URL data from being sent to the analytics server.
Technical Details
- Data Version
- 5.2
- Assigner Short Name
- GitHub_M
- Date Reserved
- 2026-05-20T17:44:09.586Z
- Cvss Version
- 4.0
- State
- PUBLISHED
Threat ID: 6a763509bf8831d5390b0168
Added to database: 08/07/2026, 19:42:01 UTC
Last enriched: 08/15/2026, 15:33:50 UTC
Last updated: 09/21/2026, 22:01:35 UTC
Views: 46
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.