Description
Element Call versions 0.5.17 through 0.19.3 report analytics data to a PostHog server, when configured to by a posthog key in config.json or by the posthogApiHost and posthogApiKey URL parameters.
Recommendation
Update the @element-hq/element-call-embedded package to the latest compatible version. Followings are version details:
- Affected version(s): >= 0.5.17, <= 0.19.3
- Patched version(s): 0.19.4
References
Related Issues
- Nuxt's route middleware is not enforced when rendering `.server.vue` pages via `/__nuxt_island/page_*` - CVE-2026-47200
- BigSweetPotatoStudio HyperChat has a Server-Side Request Forgery issue - CVE-2026-7223
- Backstage vulnerable to potential reading of SCM URLs using built in token - CVE-2026-29185
- Svelte affected by XSS in SSR `<option>` element - CVE-2026-27119
You might also like:
- Tags:
- npm
- @element-hq/element-call-embedded
Anything's wrong? Let us know Last updated on June 11, 2026


