Description
Element Call versions 0.5.17 through 0.19.3 report analytics data to a PostHog server, when configured to by a posthog key in config.json or by the posthogApiHost and posthogApiKey URL parameters.
Recommendation
Update the @element-hq/element-call-embedded package to the latest compatible version. Followings are version details:
- Affected version(s): >= 0.5.17, <= 0.19.3
- Patched version(s): 0.19.4
References
Could your website be exposed too?
SmartScanner can check your website for Element Call reports full URLs of visited pages to analytics server and gives you actionable findings to investigate.
Start a free scanRelated Issues
- Nuxt's route middleware is not enforced when rendering `.server.vue` pages via `/__nuxt_island/page_*` - CVE-2026-47200
- BigSweetPotatoStudio HyperChat has a Server-Side Request Forgery issue - CVE-2026-7223
- Backstage vulnerable to potential reading of SCM URLs using built in token - CVE-2026-29185
- Svelte affected by XSS in SSR `<option>` element - CVE-2026-27119


