CVE-2026-48007
JavaScript 취약성 분석 및 완화

개요

CVE-2026-48007 is an information disclosure vulnerability in Element Call (the @element-hq/element-call-embedded npm package) that causes full call URLs — including encryption passwords embedded in URL fragments — to be reported to a configured PostHog analytics server. It affects Element Call versions 0.5.17 through 0.19.3 and was first published on May 21, 2026, with the GitHub Advisory Database entry reviewed on June 11, 2026. The vulnerability carries a CVSS v4 base score of 8.6 (High) (GitHub Advisory, Element Security Advisory).

기술적 세부 사항

The root cause is classified as CWE-200 (Exposure of Sensitive Information to an Unauthorized Actor). Element Call's PostHog analytics integration — enabled via a posthog key in config.json or via posthogApiHost/posthogApiKey URL parameters — inadvertently included the full page URL (including the URL fragment) in several analytics fields: $initial_person_info, $session_entry_url, and $current_url. In standalone Single Page Application (SPA) deployments such as call.element.io, encryption passwords for calls are encoded directly in the URL fragment, meaning these secrets were transmitted to the PostHog server with each analytics event. The embedded package variant is technically affected but poses no practical risk to applications like Element Web, Element Desktop, or Element X (iOS/Android) because those apps distribute encryption keys over the Matrix protocol rather than encoding them in URLs (GitHub Advisory, Element Security Advisory).

영향

Successful exploitation requires an attacker to have access to the PostHog analytics data (e.g., a compromised or malicious PostHog instance, or insider access) combined with access to the encrypted media streams of the targeted call. Under those conditions, the attacker could recover the call encryption password from the analytics data and use it to decrypt intercepted media, fully compromising the confidentiality of affected calls. Availability and integrity of systems are not directly impacted; the risk is limited to confidentiality of call content for users of standalone Element Call SPA instances (GitHub Advisory).

악용 가능성

No public proof-of-concept exploit code or evidence of in-the-wild exploitation has been reported. The EPSS score is approximately 0.023% (7th percentile), indicating a low near-term probability of active exploitation (GitHub Advisory). The vulnerability is not listed in the CISA Known Exploited Vulnerabilities catalog. Exploitation is passive in nature — it relies on access to analytics backend data rather than active attack against end users — and requires both PostHog data access and interception of encrypted media streams, raising the practical exploitation bar.

착취 단계

  1. Identify a vulnerable deployment: Locate a standalone Element Call SPA instance (e.g., call.element.io or a self-hosted instance) running versions 0.5.17–0.19.3 with PostHog analytics enabled via config.json or URL parameters.
  2. Gain access to PostHog analytics data: Obtain access to the configured PostHog server — either through legitimate credentials (e.g., as an admin or analytics user), a compromised PostHog account, or by operating a malicious PostHog endpoint configured via the posthogApiHost URL parameter.
  3. Extract call URLs from analytics events: Query PostHog event data for fields $initial_person_info, $session_entry_url, or $current_url, which contain the full call URLs including URL fragments with embedded encryption passwords.
  4. Recover the encryption password: Parse the URL fragment from the collected analytics events to extract the plaintext call encryption password.
  5. Decrypt intercepted media: Combine the recovered password with a previously captured or simultaneously intercepted encrypted media stream of the targeted call to decrypt and access the call content (GitHub Advisory, Element Security Advisory).

타협의 징후

  • Network: Outbound HTTPS requests from Element Call clients to a PostHog analytics endpoint (configured host) containing URL parameters or request bodies with full call URLs including # fragments; unexpected posthogApiHost or posthogApiKey parameters in Element Call URLs, which could indicate a malicious analytics endpoint being injected.
  • Logs: Server-side or proxy logs showing POST requests to PostHog ingestion endpoints (e.g., /e/, /capture/) with event payloads containing $current_url or $session_entry_url fields that include URL fragments (the # character and subsequent content).
  • Configuration: Presence of a posthog key in config.json of a standalone Element Call deployment pointing to an unexpected or external PostHog host.

완화 및 해결 방법

Upgrade to Element Call version 0.19.4, which contains a hotfix that prevents full URLs (including fragments) from being reported to the analytics server (Element Call v0.19.4 Release). As an immediate workaround, users can opt out of analytics via the 'Feedback' tab in Element Call settings and generate new call links to invalidate any previously exposed passwords. Admins hosting standalone Element Call deployments should remove the posthog key from config.json to disable PostHog analytics entirely until the upgrade is applied (Element Security Advisory).

추가 자료


근원이 보고서는 AI를 사용하여 생성되었습니다.

관련 JavaScript 취약점:

CVE ID

심각도

점수

기술

구성 요소 이름

CISA KEV 익스플로잇

수정 사항이 있습니다.

게시된 날짜

CVE-2026-48170CRITICAL9.1
  • JavaScript logoJavaScript
  • scim-patch
아니요Aug 07, 2026
CVE-2026-48007HIGH8.6
  • JavaScript logoJavaScript
  • @element-hq/element-call-embedded
아니요Aug 07, 2026
CVE-2026-69207MEDIUM5.3
  • JavaScript logoJavaScript
  • gemini-cli
아니요Aug 07, 2026
CVE-2026-71850MEDIUM4.8
  • JavaScript logoJavaScript
  • hono
아니요Aug 07, 2026
CVE-2026-71849LOW3.7
  • JavaScript logoJavaScript
  • hono
아니요Aug 07, 2026

무료 취약성 평가

클라우드 보안 태세를 벤치마킹합니다

9개의 보안 도메인에서 클라우드 보안 관행을 평가하여 위험 수준을 벤치마킹하고 방어의 허점을 식별합니다.

평가 요청

추가 Wiz 리소스

맞춤형 데모 받기

맞춤형 데모 신청하기

"내가 본 최고의 사용자 경험은 클라우드 워크로드에 대한 완전한 가시성을 제공합니다."
데이비드 에슬릭최고정보책임자(CISO)
"Wiz는 클라우드 환경에서 무슨 일이 일어나고 있는지 볼 수 있는 단일 창을 제공합니다."
아담 플레처최고 보안 책임자(CSO)
"우리는 Wiz가 무언가를 중요한 것으로 식별하면 실제로 중요하다는 것을 알고 있습니다."
그렉 포니아토프스키위협 및 취약성 관리 책임자