Executive brief
Element Call, a video conferencing application, was found to be sending full page URLs to its analytics provider. In standalone versions of the app, these URLs can contain sensitive call encryption passwords. This could allow anyone with access to the analytics data to potentially eavesdrop on private video calls.
Technical details
Element Call (versions 0.5.17 through 0.19.3) incorrectly includes the full URL fragment in analytics data sent to PostHog via fields such as $current_url and $session_entry_url. In standalone 'SPA' deployments, call encryption passwords are often stored in the URL fragment, leading to the exposure of these credentials to the analytics platform. An attacker with access to the PostHog analytics data and the encrypted media stream could use these leaked passwords to decrypt and monitor calls. The issue is mitigated in embedded versions (like those in Element Web/Desktop) because they distribute keys via Matrix rather than the URL. The vulnerability is patched in version 0.19.4.
Affected products
- Element Element Call 0.5.17 - 0.19.3
- Element @element-hq/element-call-embedded 0.5.17 - 0.19.3
Timeline
- 2026-05-21: patched: Version 0.19.4 released
- 2026-06-11: advisory: GitHub Advisory published